Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown

CVE-2016-2039

Disclosure Date: February 20, 2016 (last updated November 25, 2024)
libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.
0
Attacker Value
Unknown

CVE-2016-2042

Disclosure Date: February 20, 2016 (last updated November 25, 2024)
phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path in an error message.
0
Attacker Value
Unknown

CVE-2016-2038

Disclosure Date: February 20, 2016 (last updated November 25, 2024)
phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
0
Attacker Value
Unknown

CVE-2015-8669

Disclosure Date: December 26, 2015 (last updated November 25, 2024)
libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
0
Attacker Value
Unknown

CVE-2015-7873

Disclosure Date: October 28, 2015 (last updated October 05, 2023)
The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter.
0