Show filters
273 Total Results
Displaying 91-100 of 273
Sort by:
Attacker Value
Unknown
CVE-2016-5099
Disclosure Date: July 05, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding.
0
Attacker Value
Unknown
CVE-2016-5098
Disclosure Date: July 05, 2016 (last updated November 25, 2024)
Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the existence of arbitrary files by triggering an error.
0
Attacker Value
Unknown
CVE-2016-5097
Disclosure Date: July 05, 2016 (last updated November 25, 2024)
phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs.
0
Attacker Value
Unknown
CVE-2016-5701
Disclosure Date: July 03, 2016 (last updated November 25, 2024)
setup/frames/index.inc.php in phpMyAdmin 4.0.10.x before 4.0.10.16, 4.4.15.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to conduct BBCode injection attacks against HTTP sessions via a crafted URI.
0
Attacker Value
Unknown
CVE-2016-5706
Disclosure Date: July 03, 2016 (last updated November 25, 2024)
js/get_scripts.js.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to cause a denial of service via a large array in the scripts parameter.
0
Attacker Value
Unknown
CVE-2016-5732
Disclosure Date: July 03, 2016 (last updated November 25, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in the partition-range implementation in templates/table/structure/display_partitions.phtml in the table-structure page in phpMyAdmin 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML via crafted table parameters.
0
Attacker Value
Unknown
CVE-2016-5733
Disclosure Date: July 03, 2016 (last updated November 25, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a crafted table name that is mishandled during privilege checking in table_row.phtml, (2) a crafted mysqld log_bin directive that is mishandled in log_selector.phtml, (3) the Transformation implementation, (4) AJAX error handling in js/ajax.js, (5) the Designer implementation, (6) the charts implementation in js/tbl_chart.js, or (7) the zoom-search implementation in rows_zoom.phtml.
0
Attacker Value
Unknown
CVE-2016-5704
Disclosure Date: July 03, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the table-structure page in phpMyAdmin 4.6.x before 4.6.3 allows remote attackers to inject arbitrary web script or HTML via vectors involving a comment.
0
Attacker Value
Unknown
CVE-2016-5702
Disclosure Date: July 03, 2016 (last updated November 25, 2024)
phpMyAdmin 4.6.x before 4.6.3, when the environment lacks a PHP_SELF value, allows remote attackers to conduct cookie-attribute injection attacks via a crafted URI.
0
Attacker Value
Unknown
CVE-2016-5703
Disclosure Date: July 03, 2016 (last updated November 25, 2024)
SQL injection vulnerability in libraries/central_columns.lib.php in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allows remote attackers to execute arbitrary SQL commands via a crafted database name that is mishandled in a central column query.
0