Show filters
273 Total Results
Displaying 11-20 of 273
Sort by:
Attacker Value
Unknown
CVE-2020-26934
Disclosure Date: October 10, 2020 (last updated February 22, 2025)
phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.
0
Attacker Value
Unknown
CVE-2020-11441
Disclosure Date: March 31, 2020 (last updated February 21, 2025)
phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable.
0
Attacker Value
Unknown
CVE-2020-10802
Disclosure Date: March 22, 2020 (last updated February 21, 2025)
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/classes/Controllers/Table/TableSearchController.php. An attacker can generate a crafted database or table name. The attack can be performed if a user attempts certain search operations on the malicious database or table.
0
Attacker Value
Unknown
CVE-2020-10803
Disclosure Date: March 22, 2020 (last updated February 21, 2025)
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which when retrieved (for instance, through the Browse tab) can trigger the XSS attack.
0
Attacker Value
Unknown
CVE-2020-10804
Disclosure Date: March 22, 2020 (last updated February 21, 2025)
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A malicious user with access to the server could create a crafted username, and then trick the victim into performing specific actions with that user account (such as editing its privileges).
0
Attacker Value
Unknown
CVE-2013-4454
Disclosure Date: February 18, 2020 (last updated February 21, 2025)
WordPress Portable phpMyAdmin Plugin 1.4.1 has Multiple Security Bypass Vulnerabilities
0
Attacker Value
Unknown
CVE-2013-4462
Disclosure Date: January 27, 2020 (last updated February 21, 2025)
WordPress Portable phpMyAdmin Plugin has an authentication bypass vulnerability
0
Attacker Value
Unknown
CVE-2020-5504
Disclosure Date: January 09, 2020 (last updated February 21, 2025)
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.
0
Attacker Value
Unknown
CVE-2019-19617
Disclosure Date: December 06, 2019 (last updated November 27, 2024)
phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php.
0
Attacker Value
Unknown
CVE-2019-18622
Disclosure Date: November 22, 2019 (last updated November 08, 2023)
An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature.
0