Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown
CVE-2008-7252
Disclosure Date: January 19, 2010 (last updated October 04, 2023)
libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2009-3697
Disclosure Date: October 16, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the PDF schema generator functionality in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified interface parameters.
0
Attacker Value
Unknown
CVE-2009-3696
Disclosure Date: October 16, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name for a MySQL table.
0
Attacker Value
Unknown
CVE-2009-2284
Disclosure Date: July 01, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark.
0
Attacker Value
Unknown
CVE-2009-1150
Disclosure Date: March 26, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the export page (display_export.lib.php) in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allow remote attackers to inject arbitrary web script or HTML via the pma_db_filename_template cookie.
0
Attacker Value
Unknown
CVE-2008-5621
Disclosure Date: December 17, 2008 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.
0
Attacker Value
Unknown
CVE-2008-4326
Disclosure Date: September 30, 2008 (last updated October 04, 2023)
The PMA_escapeJsString function in libraries/js_escape.lib.php in phpMyAdmin before 2.11.9.2, when Internet Explorer is used, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via a NUL byte inside a "</script" sequence.
0
Attacker Value
Unknown
CVE-2008-4096
Disclosure Date: September 18, 2008 (last updated October 04, 2023)
libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function.
0
Attacker Value
Unknown
CVE-2008-3457
Disclosure Date: August 04, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in setup.php in phpMyAdmin before 2.11.8 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted setup arguments. NOTE: this issue can only be exploited in limited scenarios in which the attacker must be able to modify config/config.inc.php.
0
Attacker Value
Unknown
CVE-2008-3456
Disclosure Date: August 04, 2008 (last updated October 04, 2023)
phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack.
0