cbcvebase.

Debian Phpmyadmin vulnerabilities

253 known vulnerabilities affecting debian/phpmyadmin.

Total CVEs
253
CISA KEV
1
actively exploited
Public exploits
34
Exploited in wild
3
Severity breakdown
CRITICAL18HIGH27MEDIUM95LOW113

Vulnerabilities

Page 1 of 13
CVE-2009-1151P1CRITICALCVSS 9.8KEVPoCfixed in phpmyadmin 4:3.1.3.1-1 (bookworm)2009
CVE-2009-1151 [CRITICAL] CVE-2009-1151: phpmyadmin - Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.1... Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action. Scope: local bookworm: resolved (fixed in 4:3.1.3.1-1) bullseye: resolved (fixed in 4:3.1.3.1-1) forky: resolved (fixed in 4:3.1.3.1-1) sid: resolved (fix
debian
CVE-2016-5734P1CRITICALCVSS 9.8ExploitedPoCfixed in phpmyadmin 4:4.6.3-1 (bookworm)2016
CVE-2016-5734 [CRITICAL] CVE-2016-5734: phpmyadmin - phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3... phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_replace e (aka eval) modifier, which might allow remote attackers to execute arbitrary PHP code via a crafted string, as demonstrated by the table search-and-replace implementation. Scope: local bookworm: resolved (fixe
debian
CVE-2011-2505P2MEDIUMCVSS 6.4ExploitedPoCfixed in phpmyadmin 4:3.4.3.1-1 (bookworm)2011
CVE-2011-2505 [MEDIUM] CVE-2011-2505: phpmyadmin - libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature i... libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns values to arbitrary parameters referenced in the query string, which allows remote attackers to modify the SESSION superglobal array via a crafted request, related to a "remote variable manipulation vulnerability." Scop
debian
CVE-2020-26935P2CRITICALCVSS 9.8PoCfixed in phpmyadmin 4:4.9.7+dfsg1-1 (bookworm)2020
CVE-2020-26935 [CRITICAL] CVE-2020-26935: phpmyadmin - An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x b... An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query. Scope: local bookworm: resolved (fixed in 4:4.9.7+dfsg1-1) bullseye: resolved (fixed i
debian
CVE-2020-5504P2HIGHCVSS 8.8PoCfixed in phpmyadmin 4:4.9.4+dfsg1-1 (bookworm)2020
CVE-2020-5504 [HIGH] CVE-2020-5504: phpmyadmin - In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the use... In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server. Scope: local bookworm: resolved (fixed in 4:4.9.4+dfsg1-1) bullseye: resolved (fixed in 4:4.9.4+
debian
CVE-2008-4096P3MEDIUMCVSS 8.5PoCfixed in phpmyadmin 4:2.11.8.1-2 (bookworm)2008
CVE-2008-4096 [HIGH] CVE-2008-4096: phpmyadmin - libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote... libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function. Scope: local bookworm: resolved (fixed in 4:2.11.8.1-2) bullseye: resolved (fixed in 4:2.11.8.1-2) forky: resol
debian
CVE-2018-10188P3HIGHCVSS 8.8PoCfixed in phpmyadmin 4:4.9.1+dfsg1-2 (bookworm)2018
CVE-2018-10188 [HIGH] CVE-2018-10188: phpmyadmin - phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitr... phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations.js, libraries/classes/Operations.php, and sql.php. Scope: local bookworm: resolved (fixed in 4:4.9.1+dfsg1-2) bullseye: resolved (fixed in 4:4.9.1+dfsg1-2) forky: resolved (fixed in 4:4.9.1+dfsg1-2) sid: resolved (f
debian
CVE-2019-12616P3MEDIUMCVSS 6.5PoCfixed in phpmyadmin 4:4.9.1+dfsg1-2 (bookworm)2019
CVE-2019-12616 [MEDIUM] CVE-2019-12616: phpmyadmin - An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found th... An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken tag pointing at the victim's phpMyAdmin database, and the attacker can potentially deliver a payload (such as a specific INSERT or DELETE statemen
debian
CVE-2011-2506P3LOWCVSS 7.5PoCfixed in phpmyadmin 4:3.4.3.1-1 (bookworm)2011
CVE-2011-2506 [HIGH] CVE-2011-2506: phpmyadmin - setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x ... setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restrict the presence of comment closing delimiters, which allows remote attackers to conduct static code injection attacks by leveraging the ability to modify the SESSION superglobal array. Scope: local bookworm: resolved (fixed in 4:3.4.3.1-1) bullseye
debian
CVE-2009-1285P3LOWCVSS 7.5PoCfixed in phpmyadmin 4:3.1.3.2-1 (bookworm)2009
CVE-2009-1285 [HIGH] CVE-2009-1285: phpmyadmin - Static code injection vulnerability in the getConfigFile function in setup/lib/C... Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP code into configuration files. Scope: local bookworm: resolved (fixed in 4:3.1.3.2-1) bullseye: resolved (fixed in 4:3.1.3.2-1) forky: resolved (fixed in 4:3.1.3.2-1) sid: resolved (fixe
debian
CVE-2004-1147P3CRITICALCVSS 10.0PoCfixed in phpmyadmin 2:2.6.1-rc1-1 (bookworm)2004
CVE-2004-1147 [CRITICAL] CVE-2004-1147: phpmyadmin - phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformat... phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters. Scope: local bookworm: resolved (fixed in 2:2.6.1-rc1-1) bullseye: resolved (fixed in 2:2.6.1-rc1-1) forky: resolved (fixed in 2:2.6.1-rc1-1) sid: resolved (fixed in 2:2.6.1-rc1-1) trixie:
debian
CVE-2019-6799P3MEDIUMCVSS 5.9PoCfixed in phpmyadmin 4:4.9.1+dfsg1-2 (bookworm)2019
CVE-2019-6799 [MEDIUM] CVE-2019-6799: phpmyadmin - An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServe... An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. This is related to the mysql.allow_local_infile PHP configuration, and the inadvertent ignoring of "options(MYSQLI_OPT_LOCAL
debian
CVE-2011-4107P3MEDIUMCVSS 6.5PoCfixed in phpmyadmin 4:3.4.7.1-1 (bookworm)2011
CVE-2011-4107 [MEDIUM] CVE-2011-4107: phpmyadmin - The simplexml_load_string function in the XML import plug-in (libraries/import/x... The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack. Scope: local bookworm: resolved (fixed in 4:3.4.7.1-1)
debian
CVE-2004-2631P3HIGHCVSS 7.5PoCfixed in phpmyadmin 1:2.5.7-pl1-1 (bookworm)2004
CVE-2004-2631 [HIGH] CVE-2004-2631: phpmyadmin - Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when L... Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary PHP code via a crafted table name. Scope: local bookworm: resolved (fixed in 1:2.5.7-pl1-1) bullseye: resolved (fixed in 1:2.5.7-pl1-1) forky: resolved (fixed in 1:2.5.7-pl1-1) sid: resolved (fixed in 1:2.5.7-pl1-1) tr
debian
CVE-2019-12922P3MEDIUMCVSS 6.5PoCfixed in phpmyadmin 4:4.9.1+dfsg1-2 (bookworm)2019
CVE-2019-12922 [MEDIUM] CVE-2019-12922: phpmyadmin - A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup pa... A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page. Scope: local bookworm: resolved (fixed in 4:4.9.1+dfsg1-2) bullseye: resolved (fixed in 4:4.9.1+dfsg1-2) forky: resolved (fixed in 4:4.9.1+dfsg1-2) sid: resolved (fixed in 4:4.9.1+dfsg1-2) trixie: resolved (fixed in 4:4.9.1+dfsg1-2)
debian
CVE-2022-23808P3LOWCVSS 6.1PoCfixed in phpmyadmin 4:5.1.3+dfsg1-1 (bookworm)2022
CVE-2022-23808 [MEDIUM] CVE-2022-23808: phpmyadmin - An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject m... An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection. Scope: local bookworm: resolved (fixed in 4:5.1.3+dfsg1-1) bullseye: open forky: resolved (fixed in 4:5.1.3+dfsg1-1) sid: resolved (fixed in 4:5.1.3+dfsg1-1) trixie: resolved (fixed in 4:5.1.3+dfs
debian
CVE-2015-8980P2CRITICALCVSS 9.8fixed in php-gettext 1.0.12-0.1 (bookworm)2015
CVE-2015-8980 [CRITICAL] CVE-2015-8980: php-gettext - The plural form formula in ngettext family of calls in php-gettext before 1.0.12... The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code. Scope: local bookworm: resolved (fixed in 1.0.12-0.1) bullseye: resolved (fixed in 1.0.12-0.1) sid: resolved (fixed in 1.0.12-0.1)
debian
CVE-2015-6830P3LOWCVSS 5.0PoCfixed in phpmyadmin 4:4.4.14.1-1 (bookworm)2015
CVE-2015-6830 [MEDIUM] CVE-2015-6830: phpmyadmin - libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before... libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass a multiple-reCaptcha protection mechanism against brute-force credential guessing by providing a correct response to a single reCaptcha. Scope: local bookworm: resolved (fixed in 4:4.4.14.1-1) bullseye: resolved (fi
debian
CVE-2013-3239P3MEDIUMCVSS 4.6PoCfixed in phpmyadmin 4:3.4.11.1-2 (bookworm)2013
CVE-2013-3239 [MEDIUM] CVE-2013-3239: phpmyadmin - phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory... phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary code by using a double extension in the filename of an export file, leading to interpretation of this file as an executable file by the Apache HTTP Server, as demonstrated by a .php.sql filename. Scope: local bookw
debian
CVE-2019-11768P3CRITICALCVSS 9.8fixed in phpmyadmin 4:4.9.1+dfsg1-2 (bookworm)2019
CVE-2019-11768 [CRITICAL] CVE-2019-11768: phpmyadmin - An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was report... An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an SQL injection attack through the designer feature. Scope: local bookworm: resolved (fixed in 4:4.9.1+dfsg1-2) bullseye: resolved (fixed in 4:4.9.1+dfsg1-2) forky: resolved (fixed in 4:4.9.1+dfsg1-2) sid: resolved
debian
1 / 13Next →
Debian Phpmyadmin vulnerabilities | cvebase