Show filters
568 Total Results
Displaying 481-490 of 568
Sort by:
Attacker Value
Unknown
CVE-2008-1924
Disclosure Date: April 23, 2008 (last updated October 04, 2023)
Unspecified vulnerability in phpMyAdmin before 2.11.5.2, when running on shared hosts, allows remote authenticated users with CREATE table permissions to read arbitrary files via a crafted HTTP POST request, related to use of an undefined UploadDir variable.
0
Attacker Value
Unknown
CVE-2008-1567
Disclosure Date: March 31, 2008 (last updated February 15, 2024)
phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.
0
Attacker Value
Unknown
CVE-2008-1149
Disclosure Date: March 04, 2008 (last updated October 04, 2023)
phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.
0
Attacker Value
Unknown
CVE-2008-1067
Disclosure Date: February 28, 2008 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in phpQLAdmin 2.2.7 allow remote attackers to execute arbitrary PHP code via a URL in the _SESSION[path] parameter to (1) ezmlm.php and (2) tools/update_translations.php.
0
Attacker Value
Unknown
CVE-2008-0648
Disclosure Date: February 07, 2008 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in OpenSiteAdmin 0.9.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) indexFooter.php; and (2) DatabaseManager.php, (3) FieldManager.php, (4) Filter.php, (5) Form.php, (6) FormManager.php, (7) LoginManager.php, and (8) Filters/SingleFilter.php in scripts/classes/.
0
Attacker Value
Unknown
CVE-2007-6234
Disclosure Date: December 04, 2007 (last updated October 04, 2023)
index.php in FTP Admin 0.1.0 allows remote attackers to bypass authentication and obtain administrative access via a loggedin parameter with a value of true, as demonstrated by adding a user account.
0
Attacker Value
Unknown
CVE-2007-6233
Disclosure Date: December 04, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in FTP Admin 0.1.0 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.
0
Attacker Value
Unknown
CVE-2007-6100
Disclosure Date: November 23, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in libraries/auth/cookie.auth.lib.php in phpMyAdmin before 2.11.2.2, when logins are authenticated with the cookie auth_type, allows remote attackers to inject arbitrary web script or HTML via the convcharset parameter to index.php, a different vulnerability than CVE-2005-0992.
0
Attacker Value
Unknown
CVE-2007-5976
Disclosure Date: November 15, 2007 (last updated October 04, 2023)
SQL injection vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to execute arbitrary SQL commands via the db parameter.
0
Attacker Value
Unknown
CVE-2007-5977
Disclosure Date: November 15, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to inject arbitrary web script or HTML via a hex-encoded IMG element in the db parameter in a POST request, a different vulnerability than CVE-2006-6942.
0