Show filters
568 Total Results
Displaying 381-390 of 568
Sort by:
Attacker Value
Unknown
CVE-2014-5274
Disclosure Date: August 22, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the view operations page in phpMyAdmin 4.1.x before 4.1.14.3 and 4.2.x before 4.2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted view name, related to js/functions.js.
0
Attacker Value
Unknown
CVE-2014-4955
Disclosure Date: July 20, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the PMA_TRI_getRowForList function in libraries/rte/rte_list.lib.php in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrary web script or HTML via a crafted trigger name that is improperly handled on the database triggers page.
0
Attacker Value
Unknown
CVE-2014-4954
Disclosure Date: July 20, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the PMA_getHtmlForActionLinks function in libraries/structure.lib.php in phpMyAdmin 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrary web script or HTML via a crafted table comment that is improperly handled during construction of a database structure page.
0
Attacker Value
Unknown
CVE-2014-4986
Disclosure Date: July 20, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x before 4.2.6 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) table name or (2) column name that is improperly handled during construction of an AJAX confirmation message.
0
Attacker Value
Unknown
CVE-2014-4987
Disclosure Date: July 20, 2014 (last updated October 05, 2023)
server_user_groups.php in phpMyAdmin 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6 allows remote authenticated users to bypass intended access restrictions and read the MySQL user list via a viewUsers request.
0
Attacker Value
Unknown
CVE-2014-4348
Disclosure Date: June 25, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name that is improperly handled after presence in (a) the favorite list or (b) recent tables.
0
Attacker Value
Unknown
CVE-2014-4349
Disclosure Date: June 25, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x before 4.1.14.1 and 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name that is improperly handled after a (1) hide or (2) unhide action.
0
Attacker Value
Unknown
CVE-2012-1600
Disclosure Date: May 14, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in functions.php in phpPgAdmin before 5.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) type of a function.
0
Attacker Value
Unknown
CVE-2014-2655
Disclosure Date: April 02, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the gen_show_status function in functions.inc.php in Postfix Admin (aka postfixadmin) before 2.3.7 allows remote authenticated users to execute arbitrary SQL commands via a new alias.
0
Attacker Value
Unknown
CVE-2014-1879
Disclosure Date: February 20, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in import.php in phpMyAdmin before 4.1.7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename in an import action.
0