VYPR

rpm package

opensuse/phpMyAdmin&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/phpMyAdmin&distro=openSUSE%20Tumbleweed

Vulnerabilities (163)

  • CVE-2013-4999Jul 31, 2013
    affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1

    phpMyAdmin 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to Error.class.php and Error_Handler.class.php.

  • CVE-2013-4998Jul 31, 2013
    affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1

    phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to pmd_common.php and other files.

  • CVE-2013-4997Jul 31, 2013
    affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving a JavaScript event in (1) an anchor identifier to setup/index.php or (2) a chartTitle (aka chart title) value

  • CVE-2013-4996Jul 31, 2013
    affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a crafted database name, (2) a crafted user name, (3) a crafted logo URL in the

  • CVE-2013-4995Jul 31, 2013
    affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1

    Cross-site scripting (XSS) vulnerability in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted SQL query that is not properly handled during the display of row information.

  • CVE-2013-4729Jul 4, 2013
    affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1

    import.php in phpMyAdmin 4.x before 4.0.4.1 does not properly restrict the ability of input data to specify a file format, which allows remote authenticated users to modify the GLOBALS superglobal array, and consequently change the configuration, via a crafted request.

  • CVE-2013-3242May 3, 2013
    affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1

    plugins/system/remember/remember.php in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 does not properly handle an object obtained by unserializing a cookie, which allows remote authenticated users to conduct PHP object injection attacks and cause a denial of service via unsp

  • CVE-2013-3241Apr 26, 2013
    affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1

    export.php (aka the export script) in phpMyAdmin 4.x before 4.0.0-rc3 overwrites global variables on the basis of the contents of the POST superglobal array, which allows remote authenticated users to inject values via a crafted request.

  • CVE-2013-3240Apr 26, 2013
    affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1

    Directory traversal vulnerability in the Export feature in phpMyAdmin 4.x before 4.0.0-rc3 allows remote authenticated users to read arbitrary files or possibly have unspecified other impact via a parameter that specifies a crafted export type.

  • CVE-2013-3239Apr 26, 2013
    affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1

    phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary code by using a double extension in the filename of an export file, leading to interpretation of this file as an executable file

  • CVE-2013-3238Apr 26, 2013
    affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1

    phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a /e\x00 sequence, which is not properly handled before making a preg_replace function call within the "Replace table prefix" feature.

  • CVE-2013-1937MedApr 16, 2013
    affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1

    Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might allow remote attackers to inject arbitrary web script or HTML via the (1) visualizationSettings[width] or (2) visualizationSettings[height] parameter. NOTE: a t

  • CVE-2012-5368Oct 25, 2012
    affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1

    phpMyAdmin 3.5.x before 3.5.3 uses JavaScript code that is obtained through an HTTP session to phpmyadmin.net without SSL, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by modifying this code.

  • CVE-2012-5339Oct 25, 2012
    affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.3 allow remote authenticated users to inject arbitrary web script or HTML via a crafted name of (1) an event, (2) a procedure, or (3) a trigger.

  • CVE-2012-4345Aug 21, 2012
    affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1

    Multiple cross-site scripting (XSS) vulnerabilities in the Database Structure page in phpMyAdmin 3.4.x before 3.4.11.1 and 3.5.x before 3.5.2.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) a crafted table name during table creation, or a (2) Emp

  • CVE-2012-4219Aug 21, 2012
    affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1

    show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message, related to lack of inclusion of the common.inc.php library file.

  • CVE-2011-4782Dec 22, 2011
    affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1

    Cross-site scripting (XSS) vulnerability in libraries/config/ConfigFile.class.php in the setup interface in phpMyAdmin 3.4.x before 3.4.9 allows remote attackers to inject arbitrary web script or HTML via the host parameter.

  • CVE-2011-4780Dec 22, 2011
    affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1

    Multiple cross-site scripting (XSS) vulnerabilities in libraries/display_export.lib.php in phpMyAdmin 3.4.x before 3.4.9 allow remote attackers to inject arbitrary web script or HTML via crafted URL parameters, related to the export panels in the (1) server, (2) database, and (3)

  • CVE-2011-4634Dec 22, 2011
    affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.8 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted database name, related to the Database Synchronize panel; (2) a crafted database name, related to the Database rena

  • CVE-2011-4107MedNov 17, 2011
    affected < 4.6.5.2-1.1fixed 4.6.5.2-1.1

    The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external e

Page 8 of 9