Show filters
568 Total Results
Displaying 351-360 of 568
Sort by:
Attacker Value
Unknown
CVE-2015-8669
Disclosure Date: December 26, 2015 (last updated November 25, 2024)
libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
0
Attacker Value
Unknown
CVE-2015-7873
Disclosure Date: October 28, 2015 (last updated October 05, 2023)
The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter.
0
Attacker Value
Unknown
CVE-2015-7226
Disclosure Date: September 17, 2015 (last updated October 05, 2023)
The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the display property, which allows remote attackers to obtain sensitive information via vectors related to the access handler.
0
Attacker Value
Unknown
CVE-2015-6944
Disclosure Date: September 15, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to hijack the authentication of users for requests that execute arbitrary SQL commands via the cmd parameter to sys/sys/listaBD2.jsp.
0
Attacker Value
Unknown
CVE-2015-6945
Disclosure Date: September 15, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to inject arbitrary web script or HTML via the bd parameter to sys/sys/listaBD2.jsp.
0
Attacker Value
Unknown
CVE-2015-6830
Disclosure Date: September 14, 2015 (last updated October 05, 2023)
libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass a multiple-reCaptcha protection mechanism against brute-force credential guessing by providing a correct response to a single reCaptcha.
0
Attacker Value
Unknown
CVE-2015-6518
Disclosure Date: August 18, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in phpLiteAdmin 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, (2) droptable parameter, or (3) table parameter to phpliteadmin.php.
0
Attacker Value
Unknown
CVE-2015-5509
Disclosure Date: August 18, 2015 (last updated October 05, 2023)
The Administration Views module 7.x-1.x before 7.x-1.4 for Drupal, when used with other unspecified modules, does not properly grant access to administration pages, which allows remote administrators to bypass intended restrictions via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-6517
Disclosure Date: August 18, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in phpLiteAdmin 1.1 allows remote attackers to hijack the authentication of users for requests that drop database tables via the droptable parameter to phpliteadmin.php.
0
Attacker Value
Unknown
CVE-2015-5064
Disclosure Date: June 24, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in MySql Lite Administrator (mysql-lite-administrator) beta-1 allow remote attackers to inject arbitrary web script or HTML via the table_name parameter to (1) tabella.php, (2) coloni.php, or (3) insert.php or (4) num_row parameter to coloni.php.
0