Show filters
273 Total Results
Displaying 261-270 of 273
Sort by:
Attacker Value
Unknown

CVE-2005-0459

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to select_lang.lib.php, which reveals the path in a PHP error message.
0
Attacker Value
Unknown

CVE-2005-0992

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin before 2.6.2-rc1 allows remote attackers to inject arbitrary web script or HTML via the convcharset parameter.
0
Attacker Value
Unknown

CVE-2005-0544

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
phpMyAdmin 2.6.1 allows remote attackers to obtain the full path of the server via direct requests to (1) sqlvalidator.lib.php, (2) sqlparser.lib.php, (3) select_theme.lib.php, (4) select_lang.lib.php, (5) relation_cleanup.lib.php, (6) header_meta_style.inc.php, (7) get_foreign.lib.php, (8) display_tbl_links.lib.php, (9) display_export.lib.php, (10) db_table_exists.lib.php, (11) charset_conversion.lib.php, (12) ufpdf.php, (13) mysqli.dbi.lib.php, (14) setup.php, or (15) cookie.auth.lib.php, which reveals the path in a PHP error message.
0
Attacker Value
Unknown

CVE-2004-1055

Disclosure Date: March 01, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PmaAbsoluteUri parameter, (2) the zero_rows parameter in read_dump.php, (3) the confirm form, or (4) an error message generated by the internal phpMyAdmin parser.
0
Attacker Value
Unknown

CVE-2005-0543

Disclosure Date: February 24, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerChoice parameters in select_server.lib.php, (2) the bg_color or row_no parameters in display_tbl_links.lib.php, the left_font_family parameter in theme_left.css.php, or the right_font_family parameter in theme_right.css.php.
0
Attacker Value
Unknown

CVE-2004-1148

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter.
0
Attacker Value
Unknown

CVE-2004-1147

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters.
0
Attacker Value
Unknown

CVE-2004-2631

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary PHP code via a crafted table name.
0
Attacker Value
Unknown

CVE-2004-2632

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration settings and gain unauthorized access to MySQL servers via modified $cfg['Servers'] variables.
0
Attacker Value
Unknown

CVE-2004-2630

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The MIME transformation system (transformations/text_plain__external.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.
0