Show filters
67 Total Results
Displaying 61-67 of 67
Sort by:
Attacker Value
Unknown
CVE-2016-2040
Disclosure Date: February 20, 2016 (last updated November 25, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) table name, (2) SET value, (3) search query, or (4) hostname in a Location header.
0
Attacker Value
Unknown
CVE-2016-2043
Disclosure Date: February 20, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the goToFinish1NF function in js/normalization.js in phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a table name to the normalization page.
0
Attacker Value
Unknown
CVE-2016-1927
Disclosure Date: February 20, 2016 (last updated November 25, 2024)
The suggestPassword function in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 relies on the Math.random JavaScript function, which makes it easier for remote attackers to guess passwords via a brute-force approach.
0
Attacker Value
Unknown
CVE-2016-2039
Disclosure Date: February 20, 2016 (last updated November 25, 2024)
libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.
0
Attacker Value
Unknown
CVE-2016-2042
Disclosure Date: February 20, 2016 (last updated November 25, 2024)
phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path in an error message.
0
Attacker Value
Unknown
CVE-2016-2038
Disclosure Date: February 20, 2016 (last updated November 25, 2024)
phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
0
Attacker Value
Unknown
CVE-2015-8669
Disclosure Date: December 26, 2015 (last updated November 25, 2024)
libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
0