Show filters
273 Total Results
Displaying 211-220 of 273
Sort by:
Attacker Value
Unknown
CVE-2008-3457
Disclosure Date: August 04, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in setup.php in phpMyAdmin before 2.11.8 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted setup arguments. NOTE: this issue can only be exploited in limited scenarios in which the attacker must be able to modify config/config.inc.php.
0
Attacker Value
Unknown
CVE-2008-3456
Disclosure Date: August 04, 2008 (last updated October 04, 2023)
phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack.
0
Attacker Value
Unknown
CVE-2008-3197
Disclosure Date: July 16, 2008 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2.11.7.1 allows remote attackers to perform unauthorized actions via a link or IMG tag to (1) the db parameter in the "Creating a Database" functionality (db_create.php), and (2) the convcharset and collation_connection parameters related to an unspecified program that modifies the connection character set.
0
Attacker Value
Unknown
CVE-2008-3032
Disclosure Date: July 07, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the phpMyAdmin (phpmyadmin) extension 3.0.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-2960
Disclosure Date: July 02, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when register_globals is enabled and .htaccess support is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving scripts in libraries/.
0
Attacker Value
Unknown
CVE-2008-1924
Disclosure Date: April 23, 2008 (last updated October 04, 2023)
Unspecified vulnerability in phpMyAdmin before 2.11.5.2, when running on shared hosts, allows remote authenticated users with CREATE table permissions to read arbitrary files via a crafted HTTP POST request, related to use of an undefined UploadDir variable.
0
Attacker Value
Unknown
CVE-2008-1567
Disclosure Date: March 31, 2008 (last updated February 15, 2024)
phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.
0
Attacker Value
Unknown
CVE-2008-1149
Disclosure Date: March 04, 2008 (last updated October 04, 2023)
phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.
0
Attacker Value
Unknown
CVE-2007-6100
Disclosure Date: November 23, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in libraries/auth/cookie.auth.lib.php in phpMyAdmin before 2.11.2.2, when logins are authenticated with the cookie auth_type, allows remote attackers to inject arbitrary web script or HTML via the convcharset parameter to index.php, a different vulnerability than CVE-2005-0992.
0
Attacker Value
Unknown
CVE-2007-5976
Disclosure Date: November 15, 2007 (last updated October 04, 2023)
SQL injection vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to execute arbitrary SQL commands via the db parameter.
0