Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2015-10044
Disclosure Date: January 15, 2023 (last updated February 24, 2025)
A vulnerability classified as critical was found in gophergala sqldump. This vulnerability affects unknown code. The manipulation leads to sql injection. The patch is identified as 76db54e9073b5248b8863e71a63d66a32d567d21. It is recommended to apply a patch to fix this issue. VDB-218350 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2017-1000012
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
MySQL Dumper version 1.24 is vulnerable to stored XSS when displaying the data in the database to the user
0
Attacker Value
Unknown
CVE-2012-4253
Disclosure Date: August 13, 2012 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) language parameter to learn/cubemail/install.php or (2) f parameter learn/cubemail/filemanagement.php, or execute arbitrary local files via a .. (dot dot) in the (3) config parameter to learn/cubemail/menu.php.
0
Attacker Value
Unknown
CVE-2012-4252
Disclosure Date: August 13, 2012 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to hijack the authentication of administrators for requests that (1) remove file access restriction via a deletehtaccess action, (2) drop a database via a kill value in a db action, (3) uninstall the application via a 101 value in the phase parameter to learn/cubemail/install.php, (4) delete config.php via a 2 value in the phase parameter to learn/cubemail/install.php, (5) change a password via a schutz action, or (6) execute arbitrary SQL commands via the sql_statement parameter to learn/cubemail/sql.php.
0
Attacker Value
Unknown
CVE-2012-4254
Disclosure Date: August 13, 2012 (last updated October 04, 2023)
MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information (Notices) via a direct request to (1) learn/cubemail/restore.php or (2) learn/cubemail/dump.php.
0
Attacker Value
Unknown
CVE-2012-4255
Disclosure Date: August 13, 2012 (last updated October 04, 2023)
MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information via a direct request to learn/cubemail/refresh_dblist.php, which reveals the installation path in an error message.
0
Attacker Value
Unknown
CVE-2012-4251
Disclosure Date: August 13, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to index.php, (2) phase parameter to install.php, (3) tablename or (4) dbid parameter to sql.php, or (5) filename parameter to restore.php in learn/cubemail/.
0
Attacker Value
Unknown
CVE-2010-0336
Disclosure Date: January 15, 2010 (last updated October 04, 2023)
Unspecified vulnerability in the kiddog_mysqldumper (kiddog_mysqldumper) extension 0.0.3 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown attack vectors.
0
Attacker Value
Unknown
CVE-2007-3567
Disclosure Date: July 05, 2007 (last updated October 04, 2023)
MySQLDumper 1.21b through 1.23 REV227 uses a "Limit GET" statement in the .htaccess authentication mechanism, which allows remote attackers to bypass authentication requirements via HTTP POST requests.
0
Attacker Value
Unknown
CVE-2006-5264
Disclosure Date: October 12, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in sql.php in MysqlDumper 1.21 b6 allows remote attackers to inject arbitrary web script or HTML via the db parameter.
0