rpm package
opensuse/phpMyAdmin&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/phpMyAdmin&distro=openSUSE%20Tumbleweed
Vulnerabilities (163)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2013-4999 | — | < 4.6.5.2-1.1 | 4.6.5.2-1.1 | Jul 31, 2013 | phpMyAdmin 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to Error.class.php and Error_Handler.class.php. | ||
| CVE-2013-4998 | — | < 4.6.5.2-1.1 | 4.6.5.2-1.1 | Jul 31, 2013 | phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to pmd_common.php and other files. | ||
| CVE-2013-4997 | — | < 4.6.5.2-1.1 | 4.6.5.2-1.1 | Jul 31, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving a JavaScript event in (1) an anchor identifier to setup/index.php or (2) a chartTitle (aka chart title) value | ||
| CVE-2013-4996 | — | < 4.6.5.2-1.1 | 4.6.5.2-1.1 | Jul 31, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a crafted database name, (2) a crafted user name, (3) a crafted logo URL in the | ||
| CVE-2013-4995 | — | < 4.6.5.2-1.1 | 4.6.5.2-1.1 | Jul 31, 2013 | Cross-site scripting (XSS) vulnerability in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted SQL query that is not properly handled during the display of row information. | ||
| CVE-2013-4729 | — | < 4.6.5.2-1.1 | 4.6.5.2-1.1 | Jul 4, 2013 | import.php in phpMyAdmin 4.x before 4.0.4.1 does not properly restrict the ability of input data to specify a file format, which allows remote authenticated users to modify the GLOBALS superglobal array, and consequently change the configuration, via a crafted request. | ||
| CVE-2013-3242 | — | < 4.6.5.2-1.1 | 4.6.5.2-1.1 | May 3, 2013 | plugins/system/remember/remember.php in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 does not properly handle an object obtained by unserializing a cookie, which allows remote authenticated users to conduct PHP object injection attacks and cause a denial of service via unsp | ||
| CVE-2013-3241 | — | < 4.6.5.2-1.1 | 4.6.5.2-1.1 | Apr 26, 2013 | export.php (aka the export script) in phpMyAdmin 4.x before 4.0.0-rc3 overwrites global variables on the basis of the contents of the POST superglobal array, which allows remote authenticated users to inject values via a crafted request. | ||
| CVE-2013-3240 | — | < 4.6.5.2-1.1 | 4.6.5.2-1.1 | Apr 26, 2013 | Directory traversal vulnerability in the Export feature in phpMyAdmin 4.x before 4.0.0-rc3 allows remote authenticated users to read arbitrary files or possibly have unspecified other impact via a parameter that specifies a crafted export type. | ||
| CVE-2013-3239 | — | < 4.6.5.2-1.1 | 4.6.5.2-1.1 | Apr 26, 2013 | phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary code by using a double extension in the filename of an export file, leading to interpretation of this file as an executable file | ||
| CVE-2013-3238 | — | < 4.6.5.2-1.1 | 4.6.5.2-1.1 | Apr 26, 2013 | phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a /e\x00 sequence, which is not properly handled before making a preg_replace function call within the "Replace table prefix" feature. | ||
| CVE-2013-1937 | Med | 6.1 | < 4.6.5.2-1.1 | 4.6.5.2-1.1 | Apr 16, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might allow remote attackers to inject arbitrary web script or HTML via the (1) visualizationSettings[width] or (2) visualizationSettings[height] parameter. NOTE: a t | |
| CVE-2012-5368 | — | < 4.6.5.2-1.1 | 4.6.5.2-1.1 | Oct 25, 2012 | phpMyAdmin 3.5.x before 3.5.3 uses JavaScript code that is obtained through an HTTP session to phpmyadmin.net without SSL, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by modifying this code. | ||
| CVE-2012-5339 | — | < 4.6.5.2-1.1 | 4.6.5.2-1.1 | Oct 25, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.3 allow remote authenticated users to inject arbitrary web script or HTML via a crafted name of (1) an event, (2) a procedure, or (3) a trigger. | ||
| CVE-2012-4345 | — | < 4.6.5.2-1.1 | 4.6.5.2-1.1 | Aug 21, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in the Database Structure page in phpMyAdmin 3.4.x before 3.4.11.1 and 3.5.x before 3.5.2.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) a crafted table name during table creation, or a (2) Emp | ||
| CVE-2012-4219 | — | < 4.6.5.2-1.1 | 4.6.5.2-1.1 | Aug 21, 2012 | show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message, related to lack of inclusion of the common.inc.php library file. | ||
| CVE-2011-4782 | — | < 4.6.5.2-1.1 | 4.6.5.2-1.1 | Dec 22, 2011 | Cross-site scripting (XSS) vulnerability in libraries/config/ConfigFile.class.php in the setup interface in phpMyAdmin 3.4.x before 3.4.9 allows remote attackers to inject arbitrary web script or HTML via the host parameter. | ||
| CVE-2011-4780 | — | < 4.6.5.2-1.1 | 4.6.5.2-1.1 | Dec 22, 2011 | Multiple cross-site scripting (XSS) vulnerabilities in libraries/display_export.lib.php in phpMyAdmin 3.4.x before 3.4.9 allow remote attackers to inject arbitrary web script or HTML via crafted URL parameters, related to the export panels in the (1) server, (2) database, and (3) | ||
| CVE-2011-4634 | — | < 4.6.5.2-1.1 | 4.6.5.2-1.1 | Dec 22, 2011 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.8 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted database name, related to the Database Synchronize panel; (2) a crafted database name, related to the Database rena | ||
| CVE-2011-4107 | Med | 6.5 | < 4.6.5.2-1.1 | 4.6.5.2-1.1 | Nov 17, 2011 | The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external e |
- CVE-2013-4999Jul 31, 2013affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1
phpMyAdmin 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to Error.class.php and Error_Handler.class.php.
- CVE-2013-4998Jul 31, 2013affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1
phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to pmd_common.php and other files.
- CVE-2013-4997Jul 31, 2013affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving a JavaScript event in (1) an anchor identifier to setup/index.php or (2) a chartTitle (aka chart title) value
- CVE-2013-4996Jul 31, 2013affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a crafted database name, (2) a crafted user name, (3) a crafted logo URL in the
- CVE-2013-4995Jul 31, 2013affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1
Cross-site scripting (XSS) vulnerability in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted SQL query that is not properly handled during the display of row information.
- CVE-2013-4729Jul 4, 2013affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1
import.php in phpMyAdmin 4.x before 4.0.4.1 does not properly restrict the ability of input data to specify a file format, which allows remote authenticated users to modify the GLOBALS superglobal array, and consequently change the configuration, via a crafted request.
- CVE-2013-3242May 3, 2013affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1
plugins/system/remember/remember.php in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 does not properly handle an object obtained by unserializing a cookie, which allows remote authenticated users to conduct PHP object injection attacks and cause a denial of service via unsp
- CVE-2013-3241Apr 26, 2013affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1
export.php (aka the export script) in phpMyAdmin 4.x before 4.0.0-rc3 overwrites global variables on the basis of the contents of the POST superglobal array, which allows remote authenticated users to inject values via a crafted request.
- CVE-2013-3240Apr 26, 2013affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1
Directory traversal vulnerability in the Export feature in phpMyAdmin 4.x before 4.0.0-rc3 allows remote authenticated users to read arbitrary files or possibly have unspecified other impact via a parameter that specifies a crafted export type.
- CVE-2013-3239Apr 26, 2013affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1
phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary code by using a double extension in the filename of an export file, leading to interpretation of this file as an executable file
- CVE-2013-3238Apr 26, 2013affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1
phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a /e\x00 sequence, which is not properly handled before making a preg_replace function call within the "Replace table prefix" feature.
- affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1
Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might allow remote attackers to inject arbitrary web script or HTML via the (1) visualizationSettings[width] or (2) visualizationSettings[height] parameter. NOTE: a t
- CVE-2012-5368Oct 25, 2012affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1
phpMyAdmin 3.5.x before 3.5.3 uses JavaScript code that is obtained through an HTTP session to phpmyadmin.net without SSL, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by modifying this code.
- CVE-2012-5339Oct 25, 2012affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.3 allow remote authenticated users to inject arbitrary web script or HTML via a crafted name of (1) an event, (2) a procedure, or (3) a trigger.
- CVE-2012-4345Aug 21, 2012affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1
Multiple cross-site scripting (XSS) vulnerabilities in the Database Structure page in phpMyAdmin 3.4.x before 3.4.11.1 and 3.5.x before 3.5.2.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) a crafted table name during table creation, or a (2) Emp
- CVE-2012-4219Aug 21, 2012affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1
show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message, related to lack of inclusion of the common.inc.php library file.
- CVE-2011-4782Dec 22, 2011affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1
Cross-site scripting (XSS) vulnerability in libraries/config/ConfigFile.class.php in the setup interface in phpMyAdmin 3.4.x before 3.4.9 allows remote attackers to inject arbitrary web script or HTML via the host parameter.
- CVE-2011-4780Dec 22, 2011affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1
Multiple cross-site scripting (XSS) vulnerabilities in libraries/display_export.lib.php in phpMyAdmin 3.4.x before 3.4.9 allow remote attackers to inject arbitrary web script or HTML via crafted URL parameters, related to the export panels in the (1) server, (2) database, and (3)
- CVE-2011-4634Dec 22, 2011affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.8 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted database name, related to the Database Synchronize panel; (2) a crafted database name, related to the Database rena
- affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1
The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external e
Page 8 of 9