Search CVE reports


Toggle filters

11 – 20 of 264 results


CVE-2020-26935

Medium priority
Fixed

An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this...

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-26934

Medium priority

Some fixes available 2 of 4

phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-11441

Medium priority
Ignored

phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable.

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Not affected Not affected
Show less packages

CVE-2020-10803

Medium priority

Some fixes available 1 of 3

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and...

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Not affected Fixed
Show less packages

CVE-2020-10802

Medium priority

Some fixes available 1 of 3

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions...

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Not affected Fixed
Show less packages

CVE-2020-10804

Medium priority

Some fixes available 1 of 3

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A malicious...

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Not affected Fixed
Show less packages

CVE-2020-5504

Medium priority

Some fixes available 2 of 11

In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a...

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Vulnerable Vulnerable Not affected Fixed
Show less packages

CVE-2019-19617

Medium priority

Some fixes available 3 of 4

phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php.

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Fixed
Show less packages

CVE-2019-18622

Medium priority
Not affected

An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature.

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected
Show less packages

CVE-2019-12922

Medium priority

Some fixes available 3 of 4

A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Fixed
Show less packages