Search CVE reports


Toggle filters

111 – 120 of 264 results


CVE-2016-2043

Low priority
Vulnerable

Cross-site scripting (XSS) vulnerability in the goToFinish1NF function in js/normalization.js in phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via...

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-2042

Low priority
Vulnerable

phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which...

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-2041

Medium priority
Vulnerable

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to...

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-2040

Medium priority
Vulnerable

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) table name,...

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-2039

Medium priority
Vulnerable

libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by...

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-2038

Low priority
Vulnerable

phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-1927

Medium priority
Vulnerable

The suggestPassword function in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 relies on the Math.random JavaScript function, which makes it easier for remote attackers to guess...

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Not affected Not affected
Show less packages

CVE-2015-8669

Negligible priority
Vulnerable

libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in...

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Not affected Not affected
Show less packages

CVE-2015-7873

Low priority

Some fixes available 1 of 3

The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter.

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected
Show less packages

CVE-2015-6830

Low priority

Some fixes available 1 of 3

libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass a multiple-reCaptcha protection mechanism against brute-force...

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected
Show less packages