Show filters
568 Total Results
Displaying 231-240 of 568
Sort by:
Attacker Value
Unknown
CVE-2019-1000004
Disclosure Date: February 04, 2019 (last updated November 27, 2024)
yugandhargangu JspMyAdmin2 version 1.0.6 and earlier contains a Cross Site Scripting (XSS) vulnerability in sidebar and table data that can result in Database fields aren't properly sanitized and allow code injection (Cross-Site Scripting). This attack appears to be exploitable via the payload needs to be stored in the database and the victim must see the db value in question.
0
Attacker Value
Unknown
CVE-2019-6798
Disclosure Date: January 26, 2019 (last updated November 27, 2024)
An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can be used to trigger a SQL injection attack through the designer feature.
0
Attacker Value
Unknown
CVE-2019-6799
Disclosure Date: January 26, 2019 (last updated November 27, 2024)
An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. This is related to the mysql.allow_local_infile PHP configuration, and the inadvertent ignoring of "options(MYSQLI_OPT_LOCAL_INFILE" calls.
0
Attacker Value
Unknown
CVE-2018-19968
Disclosure Date: December 11, 2018 (last updated November 27, 2024)
An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system.
0
Attacker Value
Unknown
CVE-2018-19970
Disclosure Date: December 11, 2018 (last updated November 27, 2024)
In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name.
0
Attacker Value
Unknown
CVE-2018-19969
Disclosure Date: December 11, 2018 (last updated November 27, 2024)
phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is possible to perform harmful SQL operations such as renaming databases, creating new tables/routines, deleting designer pages, adding/deleting users, updating user passwords, killing SQL processes, etc.
0
Attacker Value
Unknown
CVE-2018-16516
Disclosure Date: September 05, 2018 (last updated November 08, 2023)
helpers.py in Flask-Admin 1.5.2 has Reflected XSS via a crafted URL.
0
Attacker Value
Unknown
CVE-2018-15605
Disclosure Date: August 24, 2018 (last updated November 27, 2024)
An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted file to manipulate an authenticated user who loads that file through the import feature.
0
Attacker Value
Unknown
CVE-2016-10522
Disclosure Date: July 05, 2018 (last updated November 27, 2024)
rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens and, as a result, an attacker could hypothetically gain access to the application administrative endpoints exposed by the gem.
0
Attacker Value
Unknown
CVE-2018-12689
Disclosure Date: June 22, 2018 (last updated November 26, 2024)
phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a crafted username and password in the login panel.
0