cbcvebase.

Debian Phpmyadmin vulnerabilities

253 known vulnerabilities affecting debian/phpmyadmin.

Total CVEs
253
CISA KEV
1
actively exploited
Public exploits
34
Exploited in wild
3
Severity breakdown
CRITICAL18HIGH27MEDIUM95LOW113

Vulnerabilities

Page 4 of 13
CVE-2005-0543P4MEDIUMCVSS 4.3PoCfixed in phpmyadmin 3:2.6.1-pl2-1 (bookworm)2005
CVE-2005-0543 [MEDIUM] CVE-2005-0543: phpmyadmin - Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attac... Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerChoice parameters in select_server.lib.php, (2) the bg_color or row_no parameters in display_tbl_links.lib.php, the left_font_family parameter in theme_left.css.php, or the right_font_fami
debian
CVE-2007-5386P4MEDIUMCVSS 4.3PoCfixed in phpmyadmin 4:2.11.1.2-1 (bookworm)2007
CVE-2007-5386 [MEDIUM] CVE-2007-5386: phpmyadmin - Cross-site scripting (XSS) vulnerability in scripts/setup.php in phpMyAdmin 2.11... Cross-site scripting (XSS) vulnerability in scripts/setup.php in phpMyAdmin 2.11.1, when accessed by a browser that does not URL-encode requests, allows remote attackers to inject arbitrary web script or HTML via the query string. Scope: local bookworm: resolved (fixed in 4:2.11.1.2-1) bullseye: resolved (fixed in 4:2.11.1.2-1) forky: resolved (fixed in 4:2.11.1.
debian
CVE-2016-1927P3HIGHCVSS 7.5fixed in phpmyadmin 4:4.5.4-1 (bookworm)2016
CVE-2016-1927 [HIGH] CVE-2016-1927: phpmyadmin - The suggestPassword function in js/functions.js in phpMyAdmin 4.0.x before 4.0.1... The suggestPassword function in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 relies on the Math.random JavaScript function, which makes it easier for remote attackers to guess passwords via a brute-force approach. Scope: local bookworm: resolved (fixed in 4:4.5.4-1) bullseye: resolved (fixed in 4:4.5.4-1) forky
debian
CVE-2005-2869P4MEDIUMCVSS 4.3PoCfixed in phpmyadmin 4:2.6.4-pl1-1 (bookworm)2005
CVE-2005-2869 [MEDIUM] CVE-2005-2869: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 a... Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php. Scope: local bookworm: resolved (fixed in 4:2.6.4-pl1-1) bullseye: resolved (fixed in 4:2.6.4-pl1-1) forky: resolved (fixed
debian
CVE-2018-19968P3MEDIUMCVSS 6.5fixed in phpmyadmin 4:4.9.1+dfsg1-2 (bookworm)2018
CVE-2018-19968 [MEDIUM] CVE-2018-19968: phpmyadmin - An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local ... An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmi
debian
CVE-2007-5589P4MEDIUMCVSS 4.3PoCfixed in phpmyadmin 4:2.11.1.2-1 (bookworm)2007
CVE-2007-5589 [MEDIUM] CVE-2007-5589: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.11.1.... Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.11.1.2 allow remote attackers to inject arbitrary web script or HTML via certain input available in (1) PHP_SELF in (a) server_status.php, and (b) grab_globals.lib.php, (c) display_change_password.lib.php, and (d) common.lib.php in libraries/; and certain input available in PHP_SELF and (2
debian
CVE-2021-21252P3MEDIUMCVSS 5.3fixed in otrs2 6.0.32-4 (bullseye)2021
CVE-2021-21252 [MEDIUM] CVE-2021-21252: civicrm - The jQuery Validation Plugin provides drop-in validation for your existing forms... The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-validation before version 1.19.3 contains one or more regular expressions that are vulnerable to ReDoS (Regular Expression Denial of Service). This is fixed in 1.19.3. Scope: local bullseye: open
debian
CVE-2008-7252P3CRITICALCVSS 10.0fixed in phpmyadmin 4:3.0.0-1 (bookworm)2008
CVE-2008-7252 [CRITICAL] CVE-2008-7252: phpmyadmin - libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable fi... libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and attack vectors. Scope: local bookworm: resolved (fixed in 4:3.0.0-1) bullseye: resolved (fixed in 4:3.0.0-1) forky: resolved (fixed in 4:3.0.0-1) sid: resolved (fixed in 4:3.0.0-1) trixie: resolved (fixed in 4:3.0.0-1)
debian
CVE-2016-9862P3HIGHCVSS 7.5fixed in phpmyadmin 4:4.6.5.1-1 (bookworm)2016
CVE-2016-9862 [HIGH] CVE-2016-9862: phpmyadmin - An issue was discovered in phpMyAdmin. With a crafted login request it is possib... An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected. Scope: local bookworm: resolved (fixed in 4:4.6.5.1-1) bullseye: resolved (fixed in 4:4.6.5.1-1) forky: resolved (fixed in 4:4.6.5.1-1) sid: resolved (fixed in 4:4.6.5.1-1) trixie: resolved (fixed i
debian
CVE-2005-0992P4MEDIUMCVSS 4.3PoCfixed in phpmyadmin 3:2.6.2-rc1-1 (bookworm)2005
CVE-2005-0992 [MEDIUM] CVE-2005-0992: phpmyadmin - Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin before 2.6.2... Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin before 2.6.2-rc1 allows remote attackers to inject arbitrary web script or HTML via the convcharset parameter. Scope: local bookworm: resolved (fixed in 3:2.6.2-rc1-1) bullseye: resolved (fixed in 3:2.6.2-rc1-1) forky: resolved (fixed in 3:2.6.2-rc1-1) sid: resolved (fixed in 3:2.6.2-rc1-1) trixi
debian
CVE-2006-1803P4LOWCVSS 4.3PoCfixed in phpmyadmin 4:2.8.1-1 (bookworm)2006
CVE-2006-1803 [MEDIUM] CVE-2006-1803: phpmyadmin - Cross-site scripting (XSS) vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allo... Cross-site scripting (XSS) vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to inject arbitrary web script or HTML via the sql_query parameter. Scope: local bookworm: resolved (fixed in 4:2.8.1-1) bullseye: resolved (fixed in 4:2.8.1-1) forky: resolved (fixed in 4:2.8.1-1) sid: resolved (fixed in 4:2.8.1-1) trixie: resolved (fixed in 4:2.8
debian
CVE-2006-1258P4MEDIUMCVSS 4.3PoCfixed in phpmyadmin 4:2.8.0.2-2 (bookworm)2006
CVE-2006-1258 [MEDIUM] CVE-2006-1258: phpmyadmin - Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.1 allows remote att... Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.1 allows remote attackers to inject arbitrary web script or HTML via the set_theme parameter. Scope: local bookworm: resolved (fixed in 4:2.8.0.2-2) bullseye: resolved (fixed in 4:2.8.0.2-2) forky: resolved (fixed in 4:2.8.0.2-2) sid: resolved (fixed in 4:2.8.0.2-2) trixie: resolved (fixed in 4:2.8.0.2-
debian
CVE-2022-0813P3LOWCVSS 5.3fixed in phpmyadmin 4:5.1.3+dfsg1-1 (bookworm)2022
CVE-2022-0813 [MEDIUM] CVE-2022-0813: phpmyadmin - PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive... PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section. Scope: local bookworm: resolved (fixed in 4:5.1.3+dfsg1-1) bullseye: open forky: resolved (fixed in 4:5.1.3+dfsg1-1) sid: resolved (fixed in 4:5.1.3+dfsg1-1) trixie:
debian
CVE-2017-1000018P3LOWCVSS 7.5fixed in phpmyadmin 4:4.6.6-1 (bookworm)2017
CVE-2017-1000018 [HIGH] CVE-2017-1000018: phpmyadmin - phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication ... phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication status by using a specially crafted table name Scope: local bookworm: resolved (fixed in 4:4.6.6-1) bullseye: resolved (fixed in 4:4.6.6-1) forky: resolved (fixed in 4:4.6.6-1) sid: resolved (fixed in 4:4.6.6-1) trixie: resolved (fixed in 4:4.6.6-1)
debian
CVE-2016-6614P3MEDIUMCVSS 6.8fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6614 [MEDIUM] CVE-2016-6614: phpmyadmin - An issue was discovered in phpMyAdmin involving the %u username replacement func... An issue was discovered in phpMyAdmin involving the %u username replacement functionality of the SaveDir and UploadDir features. When the username substitution is configured, a specially-crafted user name can be used to circumvent restrictions to traverse the file system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions
debian
CVE-2011-2507P3LOWCVSS 6.5fixed in phpmyadmin 4:3.4.3.1-1 (bookworm)2011
CVE-2011-2507 [MEDIUM] CVE-2011-2507: phpmyadmin - libraries/server_synchronize.lib.php in the Synchronize implementation in phpMyA... libraries/server_synchronize.lib.php in the Synchronize implementation in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly quote regular expressions, which allows remote authenticated users to inject a PCRE e (aka PREG_REPLACE_EVAL) modifier, and consequently execute arbitrary PHP code, by leveraging the ability to modify the SESSION supe
debian
CVE-2016-6612P3MEDIUMCVSS 6.5fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6612 [MEDIUM] CVE-2016-6612: phpmyadmin - An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOCAL INFILE ... An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOCAL INFILE functionality to expose files on the server to the database system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected. Scope: local bookworm: resolved (fixed in 4:4.6.4+dfsg1-1) bullseye: resolved (fixed in 4:
debian
CVE-2008-7251P3CRITICALCVSS 10.0fixed in phpmyadmin 4:3.0.0-1 (bookworm)2008
CVE-2008-7251 [CRITICAL] CVE-2008-7251: phpmyadmin - libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 creates a temporary... libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 creates a temporary directory with 0777 permissions, which has unknown impact and attack vectors. Scope: local bookworm: resolved (fixed in 4:3.0.0-1) bullseye: resolved (fixed in 4:3.0.0-1) forky: resolved (fixed in 4:3.0.0-1) sid: resolved (fixed in 4:3.0.0-1) trixie: resolved (fixed in 4:3.0.0-1)
debian
CVE-2016-9863P3LOWCVSS 7.5fixed in phpmyadmin 4:4.6.5.1-1 (bookworm)2016
CVE-2016-9863 [HIGH] CVE-2016-9863: phpmyadmin - An issue was discovered in phpMyAdmin. With a very large request to table partit... An issue was discovered in phpMyAdmin. With a very large request to table partitioning function, it is possible to invoke a Denial of Service (DoS) attack. All 4.6.x versions (prior to 4.6.5) are affected. Scope: local bookworm: resolved (fixed in 4:4.6.5.1-1) bullseye: resolved (fixed in 4:4.6.5.1-1) forky: resolved (fixed in 4:4.6.5.1-1) sid: resolved (fixed in 4
debian
CVE-2011-2643P3MEDIUMCVSS 6.8fixed in phpmyadmin 4:3.4.3.2-1 (bookworm)2011
CVE-2011-2643 [MEDIUM] CVE-2011-2643: phpmyadmin - Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2,... Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2, when configuration storage is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a MIME-type transformation parameter. Scope: local bookworm: resolved (fixed in 4:3.4.3.2-1) bullseye: resolved (fixed in 4:3.4.3.2-1) fork
debian
Debian Phpmyadmin vulnerabilities | cvebase