phpmyadmin

272 tracked vulnerabilities.

CVE-2013-3742
phpMyAdmin 4.x < 4.0.3 - Authenticated Cross-Site Scripting via Create View Error Message
Jul 04, 2013
EPSS 0.00
CVE-2013-3241
phpMyAdmin <4.0.0-rc3 - Code Injection
Apr 26, 2013
EPSS 0.03
CVE-2013-3240
phpMyAdmin <4.0.0-rc3 - Path Traversal
Apr 26, 2013
EPSS 0.04
CVE-2013-3239
phpMyAdmin <3.5.8 and <4.0.0-rc3 - Authenticated RCE
Apr 26, 2013
EPSS 0.12
CVE-2013-3238
phpMyAdmin <3.5.8 and <4.0.0-rc3 - Authenticated RCE
Apr 26, 2013
EPSS 0.65
CVE-2013-1937 MEDIUM
phpMyAdmin < 3.5.8 - Cross-Site Scripting via visualizationSettings Parameters
Apr 16, 2013
CVSS 6.1
EPSS 0.09
CVE-2012-5469
Portable phpMyAdmin <1.3.1 - Auth Bypass
Dec 20, 2012
EPSS 0.02
CVE-2012-5368
phpMyAdmin 3.5.x < 3.5.3 - Cross-Site Scripting via Unencrypted JavaScript Fetch
Oct 25, 2012
EPSS 0.00
CVE-2012-5339
phpMyAdmin 3.5.x < 3.5.3 - Authenticated Cross-Site Scripting via Event, Procedure, or Trigger Name
Oct 25, 2012
EPSS 0.00
CVE-2012-5159
phpMyAdmin 3.5.2.2 - Remote Code Execution via Trojaned server_sync.php
Sep 25, 2012
EPSS 0.88
CVE-2012-4579
phpMyAdmin 3.5.x < 3.5.2.2 - Authenticated Cross-Site Scripting via Crafted Table Names
Aug 21, 2012
EPSS 0.00
CVE-2012-4345
phpMyAdmin 3.4.x < 3.4.11.1 and 3.5.x < 3.5.2.2 - Authenticated Cross-Site Scripting via Crafted Table Name
Aug 21, 2012
EPSS 0.00
CVE-2012-4219
phpMyAdmin 3.5.x < 3.5.2.1 - Unauthenticated Sensitive Information Exposure via Direct Request to show_config_errors.php
Aug 21, 2012
EPSS 0.00
CVE-2012-1190
phpMyAdmin 3.4.x < 3.4.10.1 - Stored Cross-Site Scripting via Database Name in Replication Setup
May 03, 2012
EPSS 0.00
CVE-2012-1902
phpMyAdmin 3.4.x < 3.4.10.2 - Sensitive Information Exposure via show_config_errors.php
Apr 06, 2012
EPSS 0.00
CVE-2011-3592
phpMyAdmin 3.4.0-3.4.5 - Authenticated Cross-Site Scripting via Database Table or Column Name
Dec 26, 2014
EPSS 0.00
CVE-2011-3591
phpMyAdmin 3.4.0-3.4.4 - Authenticated Cross-Site Scripting via Inline-Editing Confirmation Message
Dec 26, 2014
EPSS 0.00
CVE-2011-1941
phpMyAdmin 3.4.0 - Open Redirect via Redirector Feature
Jan 26, 2012
EPSS 0.00
CVE-2011-1940
phpMyAdmin 3.3.0-3.3.10 - Cross-Site Scripting via Crafted Table Name
Jan 26, 2012
EPSS 0.00
CVE-2011-4782
phpMyAdmin 3.4.0-3.4.8 - Cross-Site Scripting via Setup Host Parameter
Dec 22, 2011
EPSS 0.00
CVE-2011-4780
phpMyAdmin 3.4.x < 3.4.9 - Cross-Site Scripting via Export Panel URL Parameters
Dec 22, 2011
EPSS 0.00
CVE-2011-4634
phpMyAdmin 3.4.0-3.4.7 - Stored Cross-Site Scripting via Database Name or SQL Query
Dec 22, 2011
EPSS 0.00
CVE-2011-4107 MEDIUM
phpMyAdmin <3.4.7.1 & <3.3.10.5 - XXE Injection
Nov 17, 2011
CVSS 6.5
EPSS 0.12
CVE-2011-3646
phpMyAdmin <3.4.6 - Info Disclosure
Nov 17, 2011
EPSS 0.01
CVE-2011-4064
phpMyAdmin 3.4.x < 3.4.6 - Cross-Site Scripting via Setup Interface
Nov 01, 2011
EPSS 0.01