VYPR
Vendor

Mysqldumper

Products
1
CVEs
8
Across products
8
Status
Private

Products

1

Recent CVEs

8
  • CVE-2017-1000012MedJul 17, 2017
    risk 0.40cvss 6.1epss 0.00

    MySQL Dumper version 1.24 is vulnerable to stored XSS when displaying the data in the database to the user

  • CVE-2012-4253Aug 13, 2012
    risk 0.05cvss epss 0.30

    Multiple directory traversal vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) language parameter to learn/cubemail/install.php or (2) f parameter learn/cubemail/filemanagement.php, or execute arbitrary local files via a .. (dot dot) in the (3) config parameter to learn/cubemail/menu.php.

  • CVE-2012-4254Aug 13, 2012
    risk 0.04cvss epss 0.07

    MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information (Notices) via a direct request to (1) learn/cubemail/restore.php or (2) learn/cubemail/dump.php.

  • CVE-2012-4251Aug 13, 2012
    risk 0.04cvss epss 0.08

    Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to index.php, (2) phase parameter to install.php, (3) tablename or (4) dbid parameter to sql.php, or (5) filename parameter to restore.php in learn/cubemail/.

  • CVE-2012-4252Aug 13, 2012
    risk 0.03cvss epss 0.00

    Multiple cross-site request forgery (CSRF) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to hijack the authentication of administrators for requests that (1) remove file access restriction via a deletehtaccess action, (2) drop a database via a kill value in a db action, (3) uninstall the application via a 101 value in the phase parameter to learn/cubemail/install.php, (4) delete config.php via a 2 value in the phase parameter to learn/cubemail/install.php, (5) change a password via a schutz action, or (6) execute arbitrary SQL commands via the sql_statement parameter to learn/cubemail/sql.php.

  • CVE-2012-4255Aug 13, 2012
    risk 0.00cvss epss 0.00

    MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information via a direct request to learn/cubemail/refresh_dblist.php, which reveals the installation path in an error message.

  • CVE-2007-3567Jul 5, 2007
    risk 0.00cvss epss 0.01

    MySQLDumper 1.21b through 1.23 REV227 uses a "Limit GET" statement in the .htaccess authentication mechanism, which allows remote attackers to bypass authentication requirements via HTTP POST requests.

  • CVE-2006-5264Oct 12, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in sql.php in MysqlDumper 1.21 b6 allows remote attackers to inject arbitrary web script or HTML via the db parameter.