Show filters
273 Total Results
Displaying 161-170 of 273
Sort by:
Attacker Value
Unknown

CVE-2013-1937

Disclosure Date: April 16, 2013 (last updated November 08, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might allow remote attackers to inject arbitrary web script or HTML via the (1) visualizationSettings[width] or (2) visualizationSettings[height] parameter. NOTE: a third party reports that this is "not exploitable.
0
Attacker Value
Unknown

CVE-2012-5469

Disclosure Date: December 20, 2012 (last updated October 05, 2023)
The Portable phpMyAdmin plugin before 1.3.1 for WordPress allows remote attackers to bypass authentication and obtain phpMyAdmin console access via a direct request to wp-content/plugins/portable-phpmyadmin/wp-pma-mod.
0
Attacker Value
Unknown

CVE-2012-5339

Disclosure Date: October 25, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.3 allow remote authenticated users to inject arbitrary web script or HTML via a crafted name of (1) an event, (2) a procedure, or (3) a trigger.
0
Attacker Value
Unknown

CVE-2012-5368

Disclosure Date: October 25, 2012 (last updated October 05, 2023)
phpMyAdmin 3.5.x before 3.5.3 uses JavaScript code that is obtained through an HTTP session to phpmyadmin.net without SSL, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by modifying this code.
0
Attacker Value
Unknown

CVE-2012-5159

Disclosure Date: September 25, 2012 (last updated October 05, 2023)
phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_sync.php, which allows remote attackers to execute arbitrary PHP code via an eval injection attack.
0
Attacker Value
Unknown

CVE-2012-4579

Disclosure Date: August 21, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.2.2 allow remote authenticated users to inject arbitrary web script or HTML via a Table Operations (1) TRUNCATE or (2) DROP link for a crafted table name, (3) the Add Trigger popup within a Triggers page that references crafted table names, (4) an invalid trigger-creation attempt for a crafted table name, (5) crafted data in a table, or (6) a crafted tooltip label name during GIS data visualization, a different issue than CVE-2012-4345.
0
Attacker Value
Unknown

CVE-2012-4345

Disclosure Date: August 21, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Database Structure page in phpMyAdmin 3.4.x before 3.4.11.1 and 3.5.x before 3.5.2.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) a crafted table name during table creation, or a (2) Empty link or (3) Drop link for a crafted table name.
0
Attacker Value
Unknown

CVE-2012-4219

Disclosure Date: August 21, 2012 (last updated October 04, 2023)
show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message, related to lack of inclusion of the common.inc.php library file.
0
Attacker Value
Unknown

CVE-2012-1190

Disclosure Date: May 03, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication.js in phpMyAdmin 3.4.x before 3.4.10.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted database name.
0
Attacker Value
Unknown

CVE-2012-1902

Disclosure Date: April 06, 2012 (last updated October 04, 2023)
show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a configuration file does not exist, allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message about this missing file.
0