Debian Phpmyadmin vulnerabilities
253 known vulnerabilities affecting debian/phpmyadmin.
Total CVEs
253
CISA KEV
1
actively exploited
Public exploits
34
Exploited in wild
3
Severity breakdown
CRITICAL18HIGH27MEDIUM95LOW113
Vulnerabilities
Page 10 of 13
CVE-2006-2418P4MEDIUMCVSS 6.8fixed in phpmyadmin 4:2.8.1-1 (bookworm)2006
CVE-2006-2418 [MEDIUM] CVE-2006-2418: phpmyadmin - Cross-site scripting (XSS) vulnerabilities in certain versions of phpMyAdmin bef...
Cross-site scripting (XSS) vulnerabilities in certain versions of phpMyAdmin before 2.8.0.4 allow remote attackers to inject arbitrary web script or HTML via the db parameter in unknown scripts.
Scope: local
bookworm: resolved (fixed in 4:2.8.1-1)
bullseye: resolved (fixed in 4:2.8.1-1)
forky: resolved (fixed in 4:2.8.1-1)
sid: resolved (fixed in 4:2.8.1-1)
trixi
debian
CVE-2007-0204P4LOWCVSS 6.8fixed in phpmyadmin 4:2.9.1.1-2 (bookworm)2007
CVE-2007-0204 [MEDIUM] CVE-2007-0204: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.9.2-r...
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.9.2-rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 4:2.9.1.1-2)
bullseye: resolved (fixed in 4:2.9.1.1-2)
forky: resolved (fixed in 4
debian
CVE-2016-6610P4LOWCVSS 4.3fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6610 [MEDIUM] CVE-2016-6610: phpmyadmin - A full path disclosure vulnerability was discovered in phpMyAdmin where a user c...
A full path disclosure vulnerability was discovered in phpMyAdmin where a user can trigger a particular error in the export mechanism to discover the full path of phpMyAdmin on the disk. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Scope: local
bookworm: resolved (fixed in 4:4.6.4+d
debian
CVE-2016-2042P4LOWCVSS 5.3fixed in phpmyadmin 4:4.5.4-1 (bookworm)2016
CVE-2016-2042 [MEDIUM] CVE-2016-2042: phpmyadmin - phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers ...
phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path in an error message.
Scope: local
bookworm: resolved (fixed in 4:4.5.4-1)
bullseye: resolved (fixed in 4:4.5.4-1)
f
debian
CVE-2014-8958P4LOWCVSS 4.3fixed in phpmyadmin 4:4.2.12-1 (bookworm)2014
CVE-2014-8958 [MEDIUM] CVE-2014-8958: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4...
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.6, 4.1.x before 4.1.14.7, and 4.2.x before 4.2.12 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database, (2) table, or (3) column name that is improperly handled during rendering of the table browse page; a crafted ENUM value that is
debian
CVE-2012-1190P4LOWCVSS 4.3fixed in phpmyadmin 4:3.4.10.1-1 (bookworm)2012
CVE-2012-1190 [MEDIUM] CVE-2012-1190: phpmyadmin - Cross-site scripting (XSS) vulnerability in the replication-setup functionality ...
Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication.js in phpMyAdmin 3.4.x before 3.4.10.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted database name.
Scope: local
bookworm: resolved (fixed in 4:3.4.10.1-1)
bullseye: resolved (fixed in 4:3.4.10.1-1)
forky: resolved (fixed
debian
CVE-2013-4996P4MEDIUMCVSS 4.3fixed in phpmyadmin 4:4.0.4.2-1 (bookworm)2013
CVE-2013-4996 [MEDIUM] CVE-2013-4996: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3...
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a crafted database name, (2) a crafted user name, (3) a crafted logo URL in the navigation panel, (4) a crafted entry in a certain proxy list, or (5) crafted content
debian
CVE-2009-1150P4MEDIUMCVSS 4.3fixed in phpmyadmin 4:3.1.3.1-1 (bookworm)2009
CVE-2009-1150 [MEDIUM] CVE-2009-1150: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in the export page (display_...
Multiple cross-site scripting (XSS) vulnerabilities in the export page (display_export.lib.php) in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allow remote attackers to inject arbitrary web script or HTML via the pma_db_filename_template cookie.
Scope: local
bookworm: resolved (fixed in 4:3.1.3.1-1)
bullseye: resolved (fixed in 4:3.1.3.1-1)
forky: re
debian
CVE-2015-3903P4LOWCVSS 4.3fixed in phpmyadmin 4:4.4.6.1-1 (bookworm)2015
CVE-2015-3903 [MEDIUM] CVE-2015-3903: phpmyadmin - libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4....
libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Scope: local
bookworm: resolved (fixed i
debian
CVE-2014-4987P4LOWCVSS 4.0fixed in phpmyadmin 4:4.2.6-1 (bookworm)2014
CVE-2014-4987 [MEDIUM] CVE-2014-4987: phpmyadmin - server_user_groups.php in phpMyAdmin 4.1.x before 4.1.14.2 and 4.2.x before 4.2....
server_user_groups.php in phpMyAdmin 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6 allows remote authenticated users to bypass intended access restrictions and read the MySQL user list via a viewUsers request.
Scope: local
bookworm: resolved (fixed in 4:4.2.6-1)
bullseye: resolved (fixed in 4:4.2.6-1)
forky: resolved (fixed in 4:4.2.6-1)
sid: resolved (fixed in 4:
debian
CVE-2008-1924P4LOWCVSS 3.5fixed in phpmyadmin 4:2.11.5.2-1 (bookworm)2008
CVE-2008-1924 [LOW] CVE-2008-1924: phpmyadmin - Unspecified vulnerability in phpMyAdmin before 2.11.5.2, when running on shared ...
Unspecified vulnerability in phpMyAdmin before 2.11.5.2, when running on shared hosts, allows remote authenticated users with CREATE table permissions to read arbitrary files via a crafted HTTP POST request, related to use of an undefined UploadDir variable.
Scope: local
bookworm: resolved (fixed in 4:2.11.5.2-1)
bullseye: resolved (fixed in 4:2.11.5.2-1)
forky: res
debian
CVE-2017-1000013P4LOWCVSS 6.1fixed in phpmyadmin 4:4.6.6-1 (bookworm)2017
CVE-2017-1000013 [MEDIUM] CVE-2017-1000013: phpmyadmin - phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to an open redirect weakness
phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to an open redirect weakness
Scope: local
bookworm: resolved (fixed in 4:4.6.6-1)
bullseye: resolved (fixed in 4:4.6.6-1)
forky: resolved (fixed in 4:4.6.6-1)
sid: resolved (fixed in 4:4.6.6-1)
trixie: resolved (fixed in 4:4.6.6-1)
debian
CVE-2011-3181P4MEDIUMCVSS 4.3fixed in phpmyadmin 4:3.4.4-1 (bookworm)2011
CVE-2011-3181 [MEDIUM] CVE-2011-3181: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in the Tracking feature in p...
Multiple cross-site scripting (XSS) vulnerabilities in the Tracking feature in phpMyAdmin 3.3.x before 3.3.10.4 and 3.4.x before 3.4.4 allow remote attackers to inject arbitrary web script or HTML via a (1) table name, (2) column name, or (3) index name.
Scope: local
bookworm: resolved (fixed in 4:3.4.4-1)
bullseye: resolved (fixed in 4:3.4.4-1)
forky: resolved (
debian
CVE-2011-4064P4LOWCVSS 4.3fixed in phpmyadmin 4:3.4.6-1 (bookworm)2011
CVE-2011-4064 [MEDIUM] CVE-2011-4064: phpmyadmin - Cross-site scripting (XSS) vulnerability in the setup interface in phpMyAdmin 3....
Cross-site scripting (XSS) vulnerability in the setup interface in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value.
Scope: local
bookworm: resolved (fixed in 4:3.4.6-1)
bullseye: resolved (fixed in 4:3.4.6-1)
forky: resolved (fixed in 4:3.4.6-1)
sid: resolved (fixed in 4:3.4.6-1)
trixie: resolved (f
debian
CVE-2009-2284P4MEDIUMCVSS 4.3fixed in phpmyadmin 4:3.2.0.1-1 (bookworm)2009
CVE-2009-2284 [MEDIUM] CVE-2009-2284: phpmyadmin - Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows rem...
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark.
Scope: local
bookworm: resolved (fixed in 4:3.2.0.1-1)
bullseye: resolved (fixed in 4:3.2.0.1-1)
forky: resolved (fixed in 4:3.2.0.1-1)
sid: resolved (fixed in 4:3.2.0.1-1)
trixie: resolved (fixed in 4:3.
debian
CVE-2014-8961P4MEDIUMCVSS 4.0fixed in phpmyadmin 4:4.2.12-1 (bookworm)2014
CVE-2014-8961 [MEDIUM] CVE-2014-8961: phpmyadmin - Directory traversal vulnerability in libraries/error_report.lib.php in the error...
Directory traversal vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to obtain potentially sensitive information about a file's line count via a crafted parameter.
Scope: local
bookworm: resolved (fixed in 4:4.2.12-1)
bullseye: resolved (fix
debian
CVE-2014-9219P4MEDIUMCVSS 4.3fixed in phpmyadmin 4:4.2.12-2 (bookworm)2014
CVE-2014-9219 [MEDIUM] CVE-2014-9219: phpmyadmin - Cross-site scripting (XSS) vulnerability in the redirection feature in url.php i...
Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
Scope: local
bookworm: resolved (fixed in 4:4.2.12-2)
bullseye: resolved (fixed in 4:4.2.12-2)
forky: resolved (fixed in 4:4.2.12-2)
sid: resolved (fixed in 4:4.2.1
debian
CVE-2016-5702P4LOWCVSS 3.7fixed in phpmyadmin 4:4.6.3-1 (bookworm)2016
CVE-2016-5702 [LOW] CVE-2016-5702: phpmyadmin - phpMyAdmin 4.6.x before 4.6.3, when the environment lacks a PHP_SELF value, allo...
phpMyAdmin 4.6.x before 4.6.3, when the environment lacks a PHP_SELF value, allows remote attackers to conduct cookie-attribute injection attacks via a crafted URI.
Scope: local
bookworm: resolved (fixed in 4:4.6.3-1)
bullseye: resolved (fixed in 4:4.6.3-1)
forky: resolved (fixed in 4:4.6.3-1)
sid: resolved (fixed in 4:4.6.3-1)
trixie: resolved (fixed in 4:4.6.3-1)
debian
CVE-2005-0544P4MEDIUMCVSS 5.0fixed in phpmyadmin 3:2.6.1-pl2-1 (bookworm)2005
CVE-2005-0544 [MEDIUM] CVE-2005-0544: phpmyadmin - phpMyAdmin 2.6.1 allows remote attackers to obtain the full path of the server v...
phpMyAdmin 2.6.1 allows remote attackers to obtain the full path of the server via direct requests to (1) sqlvalidator.lib.php, (2) sqlparser.lib.php, (3) select_theme.lib.php, (4) select_lang.lib.php, (5) relation_cleanup.lib.php, (6) header_meta_style.inc.php, (7) get_foreign.lib.php, (8) display_tbl_links.lib.php, (9) display_export.lib.php, (10) db_table_exis
debian
CVE-2005-3665P4MEDIUMCVSS 4.3fixed in phpmyadmin 4:2.6.4-pl4-2 (bookworm)2005
CVE-2005-3665 [MEDIUM] CVE-2005-3665: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.7.0 a...
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.7.0 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP_HOST variable and (2) various scripts in the libraries directory that handle header generation.
Scope: local
bookworm: resolved (fixed in 4:2.6.4-pl4-2)
bullseye: resolved (fixed in 4:2.6.4-pl4-2)
forky: res
debian