Show filters
273 Total Results
Displaying 251-260 of 273
Sort by:
Attacker Value
Unknown
CVE-2005-4079
Disclosure Date: December 08, 2005 (last updated February 22, 2025)
The register_globals emulation in phpMyAdmin 2.7.0 rc1 allows remote attackers to exploit other vulnerabilities in phpMyAdmin by modifying the import_blacklist variable in grab_globals.php, which can then be used to overwrite other variables.
0
Attacker Value
Unknown
CVE-2005-3787
Disclosure Date: November 24, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl4 allow remote attackers to inject arbitrary web script or HTML via (1) the cookie-based login panel, (2) the title parameter and (3) the table creation dialog.
0
Attacker Value
Unknown
CVE-2005-3622
Disclosure Date: November 16, 2005 (last updated February 22, 2025)
phpMyAdmin 2.7.0-beta1 and earlier allows remote attackers to obtain the full path of the server via direct requests to multiple scripts in the libraries directory.
0
Attacker Value
Unknown
CVE-2005-3621
Disclosure Date: November 16, 2005 (last updated February 22, 2025)
CRLF injection vulnerability in phpMyAdmin before 2.6.4-pl4 allows remote attackers to conduct HTTP response splitting attacks via unspecified scripts.
0
Attacker Value
Unknown
CVE-2005-3301
Disclosure Date: October 24, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) left.php, (2) queryframe.php, or (3) server_databases.php.
0
Attacker Value
Unknown
CVE-2005-3300
Disclosure Date: October 23, 2005 (last updated February 22, 2025)
The register_globals emulation layer in grab_globals.php for phpMyAdmin before 2.6.4-pl3 does not perform safety checks on values in the _FILES array for uploaded files, which allows remote attackers to include arbitrary files by using direct requests to library scripts that do not use grab_globals.php, then modifying certain configuration values for the theme.
0
Attacker Value
Unknown
CVE-2005-2869
Disclosure Date: September 08, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php.
0
Attacker Value
Unknown
CVE-2005-1392
Disclosure Date: May 03, 2005 (last updated February 22, 2025)
The SQL install script in phpMyAdmin 2.6.2 is created with world-readable permissions, which allows local users to obtain the initial database password by reading the script.
0
Attacker Value
Unknown
CVE-2005-0653
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
phpMyAdmin 2.6.1 does not properly grant permissions on tables with an underscore in the name, which grants remote authenticated users more privileges than intended.
0
Attacker Value
Unknown
CVE-2005-0567
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple PHP remote file inclusion vulnerabilities in phpMyAdmin 2.6.1 allow remote attackers to execute arbitrary PHP code by modifying the (1) theme parameter to phpmyadmin.css.php or (2) cfg[Server][extension] parameter to database_interface.lib.php to reference a URL on a remote web server that contains the code.
0