Debian Phpmyadmin vulnerabilities
253 known vulnerabilities affecting debian/phpmyadmin.
Total CVEs
253
CISA KEV
1
actively exploited
Public exploits
34
Exploited in wild
3
Severity breakdown
CRITICAL18HIGH27MEDIUM95LOW113
Vulnerabilities
Page 3 of 13
CVE-2016-6621P3HIGHCVSS 8.6fixed in phpmyadmin 4:4.6.6-1 (bookworm)2016
CVE-2016-6621 [HIGH] CVE-2016-6621: phpmyadmin - The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4....
The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4:4.6.6-1)
bullseye: resolved (fixed in 4:4.6.6-1)
forky: resolved (fixed in 4:4.6.6-1)
sid: resolved (fixed in 4:4.6.6-1)
tr
debian
CVE-2016-6611P3HIGHCVSS 8.1fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6611 [HIGH] CVE-2016-6611: phpmyadmin - An issue was discovered in phpMyAdmin. A specially crafted database and/or table...
An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Scope: local
bookworm: resolved (fixed in 4:4.6.4+dfsg1-1)
bullseye: reso
debian
CVE-2016-9866P3LOWCVSS 9.8fixed in phpmyadmin 4:4.6.5.1-1 (bookworm)2016
CVE-2016-9866 [CRITICAL] CVE-2016-9866: phpmyadmin - An issue was discovered in phpMyAdmin. When the arg_separator is different from ...
An issue was discovered in phpMyAdmin. When the arg_separator is different from its default & value, the CSRF token was not properly stripped from the return URL of the preference import action. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
Scope: local
bookworm: resolved (fixed in
debian
CVE-2006-6943P4LOWCVSS 5.0PoCfixed in phpmyadmin 4:2.9.1.1-2 (bookworm)2006
CVE-2006-6943 [MEDIUM] CVE-2006-6943: phpmyadmin - PhpMyAdmin before 2.9.1.1 allows remote attackers to obtain the full server path...
PhpMyAdmin before 2.9.1.1 allows remote attackers to obtain the full server path via direct requests to (a) scripts/check_lang.php and (b) themes/darkblue_orange/layout.inc.php; and via the (1) lang[], (2) target[], (3) db[], (4) goto[], (5) table[], and (6) tbl_group[] array arguments to (c) index.php, and the (7) back[] argument to (d) sql.php; and an invalid (
debian
CVE-2016-6617P3HIGHCVSS 8.1fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6617 [HIGH] CVE-2016-6617: phpmyadmin - An issue was discovered in phpMyAdmin. A specially crafted database and/or table...
An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4) are affected.
Scope: local
bookworm: resolved (fixed in 4:4.6.4+dfsg1-1)
bullseye: resolved (fixed in 4:4.6.4+dfsg1-1)
forky: resolved (fixed in 4:4.6.4+dfsg1-1)
si
debian
CVE-2016-6606P3HIGHCVSS 8.1fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6606 [HIGH] CVE-2016-6606: phpmyadmin - An issue was discovered in cookie encryption in phpMyAdmin. The decryption of th...
An issue was discovered in cookie encryption in phpMyAdmin. The decryption of the username/password is vulnerable to a padding oracle attack. This can allow an attacker who has access to a user's browser cookie file to decrypt the username and password. Furthermore, the same initialization vector (IV) is used to hash the username and password stored in the phpMyAdm
debian
CVE-2019-19617P3CRITICALCVSS 9.8fixed in phpmyadmin 4:4.9.2+dfsg1-1 (bookworm)2019
CVE-2019-19617 [CRITICAL] CVE-2019-19617: phpmyadmin - phpMyAdmin before 4.9.2 does not escape certain Git information, related to libr...
phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php.
Scope: local
bookworm: resolved (fixed in 4:4.9.2+dfsg1-1)
bullseye: resolved (fixed in 4:4.9.2+dfsg1-1)
forky: resolved (fixed in 4:4.9.2+dfsg1-1)
sid: resolved (fixed in 4:4.9.2+dfsg1-1)
trixie: resolved (fi
debian
CVE-2017-1000017P3LOWCVSS 8.8fixed in phpmyadmin 4:4.6.6-1 (bookworm)2017
CVE-2017-1000017 [HIGH] CVE-2017-1000017: phpmyadmin - phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appro...
phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to an arbitrary MySQL server
Scope: local
bookworm: resolved (fixed in 4:4.6.6-1)
bullseye: resolved (fixed in 4:4.6.6-1)
forky: resolved (fixed in 4:4.6.6-1)
sid: resolved (fixed in 4:4.6.6-1)
trixie: resolved (fixed in 4:4.6.6-1)
debian
CVE-2020-10802P3HIGHCVSS 8.0fixed in phpmyadmin 4:4.9.5+dfsg1-1 (bookworm)2020
CVE-2020-10802 [HIGH] CVE-2020-10802: phpmyadmin - In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerabili...
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/classes/Controllers/Table/TableSearchController.php. An attacker can generate a crafted database or table name. The attack can be performed if a use
debian
CVE-2010-4480P4MEDIUMCVSS 4.3PoCfixed in phpmyadmin 4:3.3.7-3 (bookworm)2010
CVE-2010-4480 [MEDIUM] CVE-2010-4480: phpmyadmin - error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1, allows r...
error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1, allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted BBcode tag containing "@" characters, as demonstrated using "[a@url@page]".
Scope: local
bookworm: resolved (fixed in 4:3.3.7-3)
bullseye: resolved (fixed in 4:3.3.7-3)
forky: resolved (fixed in 4:3.3.7-3)
sid
debian
CVE-2016-2041P3HIGHCVSS 7.5fixed in phpmyadmin 4:4.5.4-1 (bookworm)2016
CVE-2016-2041 [HIGH] CVE-2016-2041: phpmyadmin - libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4....
libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to bypass intended access restrictions by measuring time differences.
Scope: local
bookworm: resolved (fixed in 4:4.5.4-1)
bullseye: resolved (fixed
debian
CVE-2016-6616P3HIGHCVSS 7.5fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6616 [HIGH] CVE-2016-6616: phpmyadmin - An issue was discovered in phpMyAdmin. In the "User group" and "Designer" featur...
An issue was discovered in phpMyAdmin. In the "User group" and "Designer" features, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4) and 4.4.x versions (prior to 4.4.15.8) are affected.
Scope: local
bookworm: resolved (fixed in 4:4.6.4+dfsg1-1)
bullseye: resolved (fixed in 4:4.6.4+dfsg1-1)
forky
debian
CVE-2020-10804P3HIGHCVSS 8.0fixed in phpmyadmin 4:4.9.5+dfsg1-1 (bookworm)2020
CVE-2020-10804 [HIGH] CVE-2020-10804: phpmyadmin - In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerabili...
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A malicious user with access to the server could create a crafted username, and then trick the victim into performing specific actions with that user
debian
CVE-2009-3697P3HIGHCVSS 7.5fixed in phpmyadmin 4:3.2.2.1-1 (bookworm)2009
CVE-2009-3697 [HIGH] CVE-2009-3697: phpmyadmin - SQL injection vulnerability in the PDF schema generator functionality in phpMyAd...
SQL injection vulnerability in the PDF schema generator functionality in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified interface parameters.
Scope: local
bookworm: resolved (fixed in 4:3.2.2.1-1)
bullseye: resolved (fixed in 4:3.2.2.1-1)
forky: resolved (fixed in 4:3.2.2.1-1)
sid:
debian
CVE-2016-5739P3HIGHCVSS 7.5fixed in phpmyadmin 4:4.6.3-1 (bookworm)2016
CVE-2016-5739 [HIGH] CVE-2016-5739: phpmyadmin - The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x be...
The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not use the no-referrer Content Security Policy (CSP) protection mechanism, which makes it easier for remote attackers to conduct CSRF attacks by reading an authentication token in a Referer header, related to libraries/Header.php.
Scope: local
debian
CVE-2016-9861P3LOWCVSS 7.5fixed in phpmyadmin 4:4.6.5.1-1 (bookworm)2016
CVE-2016-9861 [HIGH] CVE-2016-9861: phpmyadmin - An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it...
An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it was possible to bypass the URL white-list protection. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
Scope: local
bookworm: resolved (fixed in 4:4.6.5.1-1)
bullseye: resolved (fixed in 4:4.6.5.1-1)
forky: r
debian
CVE-2018-19969P3HIGHCVSS 8.8fixed in phpmyadmin 4:4.9.1+dfsg1-2 (bookworm)2018
CVE-2018-19969 [HIGH] CVE-2018-19969: phpmyadmin - phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of C...
phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is possible to perform harmful SQL operations such as renaming databases, creating new tables/routines, deleting designer pages, adding/deleting users, updating user passwords, killing SQL processes, etc.
Scope: local
b
debian
CVE-2008-4775P4LOWCVSS 6.8PoCfixed in phpmyadmin 4:2.11.8.1-4 (bookworm)2008
CVE-2008-4775 [MEDIUM] CVE-2008-4775: phpmyadmin - Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and...
Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.
Scope: local
bookworm: resolved (fixed in 4:2.11.8.1-4
debian
CVE-2004-2630P3HIGHCVSS 7.5fixed in phpmyadmin 2:2.6.0-pl2-1 (bookworm)2004
CVE-2004-2630 [HIGH] CVE-2004-2630: phpmyadmin - The MIME transformation system (transformations/text_plain__external.inc.php) in...
The MIME transformation system (transformations/text_plain__external.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.
Scope: local
bookworm: resolved (fixed in 2:2.6.0-pl2-1)
bullseye: resolved (fixed in 2:2.6.0-pl2-1)
forky: resolved (fixed in 2:2.6.0-pl2-1)
sid: res
debian
CVE-2005-3301P4MEDIUMCVSS 4.3PoCfixed in phpmyadmin 4:2.6.4-pl3-1 (bookworm)2005
CVE-2005-3301 [MEDIUM] CVE-2005-3301: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-p...
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) left.php, (2) queryframe.php, or (3) server_databases.php.
Scope: local
bookworm: resolved (fixed in 4:2.6.4-pl3-1)
bullseye: resolved (fixed in 4:2.6.4-pl3-1)
forky: resolved (fixed in 4:2.6
debian