Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Very High
CVE-2005-3299
Disclosure Date: October 23, 2005 (last updated October 04, 2023)
PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array.
3
Attacker Value
Unknown
CVE-2009-2284
Disclosure Date: July 01, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark.
0
Attacker Value
Unknown
CVE-2008-4326
Disclosure Date: September 30, 2008 (last updated October 04, 2023)
The PMA_escapeJsString function in libraries/js_escape.lib.php in phpMyAdmin before 2.11.9.2, when Internet Explorer is used, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via a NUL byte inside a "</script" sequence.
0
Attacker Value
Unknown
CVE-2008-3197
Disclosure Date: July 16, 2008 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2.11.7.1 allows remote attackers to perform unauthorized actions via a link or IMG tag to (1) the db parameter in the "Creating a Database" functionality (db_create.php), and (2) the convcharset and collation_connection parameters related to an unspecified program that modifies the connection character set.
0
Attacker Value
Unknown
CVE-2006-5718
Disclosure Date: November 04, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in error.php in phpMyAdmin 2.6.4 through 2.9.0.2 allows remote attackers to inject arbitrary web script or HTML via UTF-7 or US-ASCII encoded characters, which are injected into an error message, as demonstrated by a request with a utf7 charset parameter accompanied by UTF-7 data.
0
Attacker Value
Unknown
CVE-2006-3388
Disclosure Date: July 06, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via the table parameter.
0
Attacker Value
Unknown
CVE-2006-1678
Disclosure Date: April 11, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.8.0.3 allow remote attackers to inject arbitrary web script or HTML via unknown vectors in unspecified scripts in the themes directory.
0
Attacker Value
Unknown
CVE-2005-3665
Disclosure Date: December 08, 2005 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.7.0 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP_HOST variable and (2) various scripts in the libraries directory that handle header generation.
0
Attacker Value
Unknown
CVE-2005-3787
Disclosure Date: November 24, 2005 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl4 allow remote attackers to inject arbitrary web script or HTML via (1) the cookie-based login panel, (2) the title parameter and (3) the table creation dialog.
0
Attacker Value
Unknown
CVE-2005-3622
Disclosure Date: November 16, 2005 (last updated October 04, 2023)
phpMyAdmin 2.7.0-beta1 and earlier allows remote attackers to obtain the full path of the server via direct requests to multiple scripts in the libraries directory.
0