Debian Phpmyadmin vulnerabilities
253 known vulnerabilities affecting debian/phpmyadmin.
Total CVEs
253
CISA KEV
1
actively exploited
Public exploits
34
Exploited in wild
3
Severity breakdown
CRITICAL18HIGH27MEDIUM95LOW113
Vulnerabilities
Page 2 of 13
CVE-2008-5621P3MEDIUMCVSS 6.0PoCfixed in phpmyadmin 4:2.11.8.1-5 (bookworm)2008
CVE-2008-5621 [MEDIUM] CVE-2008-5621: phpmyadmin - Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11...
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be l
debian
CVE-2016-5703P3CRITICALCVSS 9.8fixed in phpmyadmin 4:4.6.3-1 (bookworm)2016
CVE-2016-5703 [CRITICAL] CVE-2016-5703: phpmyadmin - SQL injection vulnerability in libraries/central_columns.lib.php in phpMyAdmin 4...
SQL injection vulnerability in libraries/central_columns.lib.php in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allows remote attackers to execute arbitrary SQL commands via a crafted database name that is mishandled in a central column query.
Scope: local
bookworm: resolved (fixed in 4:4.6.3-1)
bullseye: resolved (fixed in 4:4.6.3-1)
forky: resolve
debian
CVE-2019-6798P3CRITICALCVSS 9.8fixed in phpmyadmin 4:4.9.1+dfsg1-2 (bookworm)2019
CVE-2019-6798 [CRITICAL] CVE-2019-6798: phpmyadmin - An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported...
An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can be used to trigger a SQL injection attack through the designer feature.
Scope: local
bookworm: resolved (fixed in 4:4.9.1+dfsg1-2)
bullseye: resolved (fixed in 4:4.9.1+dfsg1-2)
forky: resolved (fixed in 4:4.9.1+dfsg1-2)
sid: resolved (fixed in
debian
CVE-2016-6620P3CRITICALCVSS 9.8fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6620 [CRITICAL] CVE-2016-6620: phpmyadmin - An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserializ...
An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. The unserialization can result in code execution because of the interaction with object instantiation and autoloading. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prio
debian
CVE-2010-3055P3HIGHCVSS 7.5fixed in phpmyadmin 4:3.0.0 (bookworm)2010
CVE-2010-3055 [HIGH] CVE-2010-3055: phpmyadmin - The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x befo...
The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before 2.11.10.1 does not properly restrict key names in its output file, which allows remote attackers to execute arbitrary PHP code via a crafted POST request.
Scope: local
bookworm: resolved (fixed in 4:3.0.0)
bullseye: resolved (fixed in 4:3.0.0)
forky: resolved (fixed in 4:3.0.0)
sid:
debian
CVE-2014-9218P4LOWCVSS 5.0PoCfixed in phpmyadmin 4:4.2.12-2 (bookworm)2014
CVE-2014-9218 [MEDIUM] CVE-2014-9218: phpmyadmin - libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.1...
libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a denial of service (resource consumption) via a long password.
Scope: local
bookworm: resolved (fixed in 4:4.2.12-2)
bullseye: resolved (fixed in 4:4.2.12-2)
forky: resolved (fixed in 4:4.2.12-2)
sid: resolved (fixed in
debian
CVE-2016-6629P3CRITICALCVSS 9.8fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6629 [CRITICAL] CVE-2016-6629: phpmyadmin - An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'...
An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive. An attacker could reuse certain cookie values in a way of bypassing the servers defined by ArbitraryServerRegexp. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Scope: local
bo
debian
CVE-2004-0129P4MEDIUMCVSS 5.0PoCfixed in phpmyadmin 2:2.6.0-pl2 (bookworm)2004
CVE-2004-0129 [MEDIUM] CVE-2004-0129: phpmyadmin - Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier ...
Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in the what parameter.
Scope: local
bookworm: resolved (fixed in 2:2.6.0-pl2)
bullseye: resolved (fixed in 2:2.6.0-pl2)
forky: resolved (fixed in 2:2.6.0-pl2)
sid: resolved (fixed in 2:2.6.0-pl2)
trixie: resolv
debian
CVE-2016-9849P3CRITICALCVSS 9.8fixed in phpmyadmin 4:4.6.5.1-1 (bookworm)2016
CVE-2016-9849 [CRITICAL] CVE-2016-9849: phpmyadmin - An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restri...
An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restriction ($cfg['Servers'][$i]['AllowRoot']) and deny rules for username by using Null Byte in the username. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
Scope: local
bookworm: resolved (fixed in 4:4.6.5.1
debian
CVE-2005-3299P4HIGHCVSS 5.0PoCfixed in phpmyadmin 4:2.6.4-pl2-1 (bookworm)2005
CVE-2005-3299 [MEDIUM] CVE-2005-3299: phpmyadmin - PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and...
PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array.
Scope: local
bookworm: resolved (fixed in 4:2.6.4-pl2-1)
bullseye: resolved (fixed in 4:2.6.4-pl2-1)
forky: resolved (fixed in 4:2.6.4-pl2-1)
sid: resolved (f
debian
CVE-2019-18622P3CRITICALCVSS 9.8fixed in phpmyadmin 4:4.9.2+dfsg1-1 (bookworm)2019
CVE-2019-18622 [CRITICAL] CVE-2019-18622: phpmyadmin - An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table nam...
An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature.
Scope: local
bookworm: resolved (fixed in 4:4.9.2+dfsg1-1)
bullseye: resolved (fixed in 4:4.9.2+dfsg1-1)
forky: resolved (fixed in 4:4.9.2+dfsg1-1)
sid: resolved (fixed in 4:4.9.2+dfsg1-1)
trixie: resolv
debian
CVE-2016-6609P3HIGHCVSS 8.8fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6609 [HIGH] CVE-2016-6609: phpmyadmin - An issue was discovered in phpMyAdmin. A specially crafted database name could b...
An issue was discovered in phpMyAdmin. A specially crafted database name could be used to run arbitrary PHP commands through the array export feature. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Scope: local
bookworm: resolved (fixed in 4:4.6.4+dfsg1-1)
bullseye: resolved (fixed in 4
debian
CVE-2016-6631P3HIGHCVSS 7.5fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6631 [HIGH] CVE-2016-6631: phpmyadmin - An issue was discovered in phpMyAdmin. A user can execute a remote code executio...
An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmin is being run as a CGI application. Under certain server configurations, a user can pass a query string which is executed as a command-line argument by the file generator_plugin.sh. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.
debian
CVE-2017-18264P3CRITICALCVSS 9.8fixed in phpmyadmin 4:4.6.6-2 (bookworm)2017
CVE-2017-18264 [CRITICAL] CVE-2017-18264: phpmyadmin - An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0...
An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0.10.20, 4.4.x, 4.6.x, and 4.7.0 prereleases. The restrictions caused by $cfg['Servers'][$i]['AllowNoPassword'] = false are bypassed under certain PHP versions (e.g., version 5). This can allow the login of users who have no password set even if the administrator has set $cfg['Serv
debian
CVE-2016-9865P3CRITICALCVSS 9.8fixed in phpmyadmin 4:4.6.5.1-1 (bookworm)2016
CVE-2016-9865 [CRITICAL] CVE-2016-9865: phpmyadmin - An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing...
An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
Scope: local
bookworm: resolved (fixed in 4:4.6.5.1-1)
bullseye: resol
debian
CVE-2016-6619P3HIGHCVSS 8.8fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6619 [HIGH] CVE-2016-6619: phpmyadmin - An issue was discovered in phpMyAdmin. In the user interface preference feature,...
An issue was discovered in phpMyAdmin. In the user interface preference feature, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Scope: local
bookworm: resolved (fixed in 4:4.6.4+dfsg1-1)
bullseye: resolv
debian
CVE-2016-6633P3LOWCVSS 8.1fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6633 [HIGH] CVE-2016-6633: phpmyadmin - An issue was discovered in phpMyAdmin. phpMyAdmin can be used to trigger a remot...
An issue was discovered in phpMyAdmin. phpMyAdmin can be used to trigger a remote code execution attack against certain PHP installations that are running with the dbase extension. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Scope: local
bookworm: resolved (fixed in 4:4.6.4+dfsg1-1)
debian
CVE-2020-22452P3CRITICALCVSS 9.8fixed in phpmyadmin 4:5.0.4+dfsg1-1 (bookworm)2020
CVE-2020-22452 [CRITICAL] CVE-2020-22452: phpmyadmin - SQL Injection vulnerability in function getTableCreationQuery in CreateAddField....
SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.
Scope: local
bookworm: resolved (fixed in 4:5.0.4+dfsg1-1)
bullseye: resolved (fixed in 4:5.0.4+dfsg1-1)
forky: resolved (fixed in 4:5.0.4+dfsg1-1)
sid: resolved (fixed in
debian
CVE-2016-9864P3HIGHCVSS 7.5fixed in phpmyadmin 4:4.6.5.1-1 (bookworm)2016
CVE-2016-9864 [HIGH] CVE-2016-9864: phpmyadmin - An issue was discovered in phpMyAdmin. With a crafted username or a table name, ...
An issue was discovered in phpMyAdmin. With a crafted username or a table name, it was possible to inject SQL statements in the tracking functionality that would run with the privileges of the control user. This gives read and write access to the tables of the configuration storage database, and if the control user has the necessary privileges, read access to some
debian
CVE-2006-6942P4MEDIUMCVSS 6.8PoCfixed in phpmyadmin 4:2.9.1.1-2 (bookworm)2006
CVE-2006-6942 [MEDIUM] CVE-2006-6942: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1...
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1) a comment for a table name, as exploited through (a) db_operations.php, (2) the db parameter to (b) db_create.php, (3) the newname parameter to db_operations.php, the (4) query_history_latest, (5) query_history_lat
debian