Search CVE reports


Toggle filters

81 – 90 of 264 results


CVE-2016-6613

Negligible priority
Vulnerable

An issue was discovered in phpMyAdmin. A user can specially craft a symlink on disk, to a file which phpMyAdmin is permitted to read but the user is not, which phpMyAdmin will then expose to the user. All 4.6.x versions (prior to...

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-6612

Medium priority
Vulnerable

An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOCAL INFILE functionality to expose files on the server to the database system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x...

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-6611

Medium priority
Vulnerable

An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to...

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-6610

Negligible priority
Vulnerable

A full path disclosure vulnerability was discovered in phpMyAdmin where a user can trigger a particular error in the export mechanism to discover the full path of phpMyAdmin on the disk. All 4.6.x versions (prior to 4.6.4), 4.4.x...

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-6609

Medium priority

Some fixes available 2 of 3

An issue was discovered in phpMyAdmin. A specially crafted database name could be used to run arbitrary PHP commands through the array export feature. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and...

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Not affected
Show less packages

CVE-2016-6608

Medium priority
Not affected

XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted database names can trigger the XSS attack. All 4.6.x versions (prior to 4.6.4) are affected.

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin
Show less packages

CVE-2016-6607

Medium priority
Vulnerable

XSS issues were discovered in phpMyAdmin. This affects Zoom search (specially crafted column content can be used to trigger an XSS attack); GIS editor (certain fields in the graphical GIS editor are not properly escaped and can be...

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-6606

High priority

Some fixes available 2 of 3

An issue was discovered in cookie encryption in phpMyAdmin. The decryption of the username/password is vulnerable to a padding oracle attack. This can allow an attacker who has access to a user's browser cookie file to decrypt the...

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected
Show less packages

CVE-2016-4412

Medium priority
Vulnerable

An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token....

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-5099

Medium priority
Vulnerable

Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding.

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Not affected Not affected
Show less packages