Show filters
568 Total Results
Displaying 451-460 of 568
Sort by:
Attacker Value
Unknown

CVE-2008-7251

Disclosure Date: January 19, 2010 (last updated October 04, 2023)
libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 creates a temporary directory with 0777 permissions, which has unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2009-4605

Disclosure Date: January 19, 2010 (last updated October 04, 2023)
scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-7252

Disclosure Date: January 19, 2010 (last updated October 04, 2023)
libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2009-4427

Disclosure Date: December 28, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in cmd.php in phpLDAPadmin 1.1.0.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cmd parameter.
0
Attacker Value
Unknown

CVE-2009-3697

Disclosure Date: October 16, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the PDF schema generator functionality in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified interface parameters.
0
Attacker Value
Unknown

CVE-2009-3696

Disclosure Date: October 16, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name for a MySQL table.
0
Attacker Value
Unknown

CVE-2009-2571

Disclosure Date: July 22, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in index.php in VerliAdmin 0.3.7 and 0.3.8 allow remote attackers to inject arbitrary web script or HTML via (1) the URI, (2) the q parameter, (3) the nick parameter, or (4) the nick parameter in a bantest action.
0
Attacker Value
Unknown

CVE-2009-2557

Disclosure Date: July 21, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in system/download.php in Admin News Tools 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the fichier parameter.
0
Attacker Value
Unknown

CVE-2009-2558

Disclosure Date: July 21, 2009 (last updated October 04, 2023)
system/message.php in Admin News Tools 2.5 does not properly restrict access, which allows remote attackers to post news messages via a direct request.
0
Attacker Value
Unknown

CVE-2009-2284

Disclosure Date: July 01, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark.
0