Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown
CVE-2016-2039
Disclosure Date: February 20, 2016 (last updated November 25, 2024)
libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.
0
Attacker Value
Unknown
CVE-2016-2042
Disclosure Date: February 20, 2016 (last updated November 25, 2024)
phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path in an error message.
0
Attacker Value
Unknown
CVE-2016-2038
Disclosure Date: February 20, 2016 (last updated November 25, 2024)
phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
0
Attacker Value
Unknown
CVE-2015-8669
Disclosure Date: December 26, 2015 (last updated November 25, 2024)
libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
0
Attacker Value
Unknown
CVE-2015-7873
Disclosure Date: October 28, 2015 (last updated October 05, 2023)
The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter.
0