Show filters
569 Total Results
Displaying 201-210 of 569
Sort by:
Attacker Value
Unknown
CVE-2020-27163
Disclosure Date: October 16, 2020 (last updated February 22, 2025)
phpRedisAdmin before 1.13.2 allows XSS via the login.php username parameter.
0
Attacker Value
Unknown
CVE-2020-26935
Disclosure Date: October 10, 2020 (last updated February 22, 2025)
An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.
0
Attacker Value
Unknown
CVE-2020-26934
Disclosure Date: October 10, 2020 (last updated February 22, 2025)
phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.
0
Attacker Value
Unknown
CVE-2020-25540
Disclosure Date: September 14, 2020 (last updated February 22, 2025)
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on a remote server via GET request encode parameter.
0
Attacker Value
Unknown
CVE-2020-24316
Disclosure Date: August 26, 2020 (last updated February 22, 2025)
WP Plugin Rednumber Admin Menu v1.1 and lower does not sanitize the value of the "role" GET parameter before echoing it back out to the user. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.
0
Attacker Value
Unknown
CVE-2020-13433
Disclosure Date: May 24, 2020 (last updated February 21, 2025)
Jason2605 AdminPanel 4.0 allows SQL Injection via the editPlayer.php hidden parameter.
0
Attacker Value
Unknown
CVE-2020-11441
Disclosure Date: March 31, 2020 (last updated February 21, 2025)
phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable.
0
Attacker Value
Unknown
CVE-2020-10802
Disclosure Date: March 22, 2020 (last updated February 21, 2025)
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/classes/Controllers/Table/TableSearchController.php. An attacker can generate a crafted database or table name. The attack can be performed if a user attempts certain search operations on the malicious database or table.
0
Attacker Value
Unknown
CVE-2020-10803
Disclosure Date: March 22, 2020 (last updated February 21, 2025)
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which when retrieved (for instance, through the Browse tab) can trigger the XSS attack.
0
Attacker Value
Unknown
CVE-2020-10804
Disclosure Date: March 22, 2020 (last updated February 21, 2025)
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A malicious user with access to the server could create a crafted username, and then trick the victim into performing specific actions with that user account (such as editing its privileges).
0