Show filters
569 Total Results
Displaying 201-210 of 569
Sort by:
Attacker Value
Unknown

CVE-2020-27163

Disclosure Date: October 16, 2020 (last updated February 22, 2025)
phpRedisAdmin before 1.13.2 allows XSS via the login.php username parameter.
Attacker Value
Unknown

CVE-2020-26935

Disclosure Date: October 10, 2020 (last updated February 22, 2025)
An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.
Attacker Value
Unknown

CVE-2020-26934

Disclosure Date: October 10, 2020 (last updated February 22, 2025)
phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.
Attacker Value
Unknown

CVE-2020-25540

Disclosure Date: September 14, 2020 (last updated February 22, 2025)
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on a remote server via GET request encode parameter.
Attacker Value
Unknown

CVE-2020-24316

Disclosure Date: August 26, 2020 (last updated February 22, 2025)
WP Plugin Rednumber Admin Menu v1.1 and lower does not sanitize the value of the "role" GET parameter before echoing it back out to the user. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.
Attacker Value
Unknown

CVE-2020-13433

Disclosure Date: May 24, 2020 (last updated February 21, 2025)
Jason2605 AdminPanel 4.0 allows SQL Injection via the editPlayer.php hidden parameter.
Attacker Value
Unknown

CVE-2020-11441

Disclosure Date: March 31, 2020 (last updated February 21, 2025)
phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable.
Attacker Value
Unknown

CVE-2020-10802

Disclosure Date: March 22, 2020 (last updated February 21, 2025)
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/classes/Controllers/Table/TableSearchController.php. An attacker can generate a crafted database or table name. The attack can be performed if a user attempts certain search operations on the malicious database or table.
Attacker Value
Unknown

CVE-2020-10803

Disclosure Date: March 22, 2020 (last updated February 21, 2025)
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which when retrieved (for instance, through the Browse tab) can trigger the XSS attack.
Attacker Value
Unknown

CVE-2020-10804

Disclosure Date: March 22, 2020 (last updated February 21, 2025)
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A malicious user with access to the server could create a crafted username, and then trick the victim into performing specific actions with that user account (such as editing its privileges).