Show filters
568 Total Results
Displaying 321-330 of 568
Sort by:
Attacker Value
Unknown
CVE-2016-6630
Disclosure Date: December 11, 2016 (last updated November 25, 2024)
An issue was discovered in phpMyAdmin. An authenticated user can trigger a denial-of-service (DoS) attack by entering a very long password at the change password dialog. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
0
Attacker Value
Unknown
CVE-2016-1000126
Disclosure Date: October 10, 2016 (last updated November 25, 2024)
Reflected XSS in wordpress plugin admin-font-editor v1.8
0
Attacker Value
Unknown
CVE-2016-5099
Disclosure Date: July 05, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding.
0
Attacker Value
Unknown
CVE-2016-5098
Disclosure Date: July 05, 2016 (last updated November 25, 2024)
Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the existence of arbitrary files by triggering an error.
0
Attacker Value
Unknown
CVE-2016-5097
Disclosure Date: July 05, 2016 (last updated November 25, 2024)
phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs.
0
Attacker Value
Unknown
CVE-2016-5701
Disclosure Date: July 03, 2016 (last updated November 25, 2024)
setup/frames/index.inc.php in phpMyAdmin 4.0.10.x before 4.0.10.16, 4.4.15.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to conduct BBCode injection attacks against HTTP sessions via a crafted URI.
0
Attacker Value
Unknown
CVE-2016-5706
Disclosure Date: July 03, 2016 (last updated November 25, 2024)
js/get_scripts.js.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to cause a denial of service via a large array in the scripts parameter.
0
Attacker Value
Unknown
CVE-2016-5732
Disclosure Date: July 03, 2016 (last updated November 25, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in the partition-range implementation in templates/table/structure/display_partitions.phtml in the table-structure page in phpMyAdmin 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML via crafted table parameters.
0
Attacker Value
Unknown
CVE-2016-5733
Disclosure Date: July 03, 2016 (last updated November 25, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a crafted table name that is mishandled during privilege checking in table_row.phtml, (2) a crafted mysqld log_bin directive that is mishandled in log_selector.phtml, (3) the Transformation implementation, (4) AJAX error handling in js/ajax.js, (5) the Designer implementation, (6) the charts implementation in js/tbl_chart.js, or (7) the zoom-search implementation in rows_zoom.phtml.
0
Attacker Value
Unknown
CVE-2016-5704
Disclosure Date: July 03, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the table-structure page in phpMyAdmin 4.6.x before 4.6.3 allows remote attackers to inject arbitrary web script or HTML via vectors involving a comment.
0