cbcvebase.

Debian Phpmyadmin vulnerabilities

253 known vulnerabilities affecting debian/phpmyadmin.

Total CVEs
253
CISA KEV
1
actively exploited
Public exploits
34
Exploited in wild
3
Severity breakdown
CRITICAL18HIGH27MEDIUM95LOW113

Vulnerabilities

Page 5 of 13
CVE-2017-1000016P3LOWCVSS 7.5fixed in phpmyadmin 4:4.6.6-1 (bookworm)2017
CVE-2017-1000016 [HIGH] CVE-2017-1000016: phpmyadmin - A weakness was discovered where an attacker can inject arbitrary values in to th... A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of an incomplete fix from PMASA-2016-18. Scope: local bookworm: resolved (fixed in 4:4.6.6-1) bullseye: resolved (fixed in 4:4.6.6-1) forky: resolved (fixed in 4:4.6.6-1) sid: resolved (fixed in 4:4.6.6-1) trixie: resolved (fixed in 4:4.6.6-1)
debian
CVE-2013-5003P3MEDIUMCVSS 6.5fixed in phpmyadmin 4:4.0.4.2-1 (bookworm)2013
CVE-2013-5003 [MEDIUM] CVE-2013-5003: phpmyadmin - Multiple SQL injection vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.... Multiple SQL injection vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote authenticated users to execute arbitrary SQL commands via (1) the scale parameter to pmd_pdf.php or (2) the pdf_page_number parameter to schema_export.php. Scope: local bookworm: resolved (fixed in 4:4.0.4.2-1) bullseye: resolved (fixed in 4:4.0.4.2-1)
debian
CVE-2004-2632P4HIGHCVSS 7.5fixed in phpmyadmin 1:2.5.7-pl1-1 (bookworm)2004
CVE-2004-2632 [HIGH] CVE-2004-2632: phpmyadmin - phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration set... phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration settings and gain unauthorized access to MySQL servers via modified $cfg['Servers'] variables. Scope: local bookworm: resolved (fixed in 1:2.5.7-pl1-1) bullseye: resolved (fixed in 1:2.5.7-pl1-1) forky: resolved (fixed in 1:2.5.7-pl1-1) sid: resolved (fixed in 1:2.5.7-pl1-1) trixie: resolv
debian
CVE-2016-5706P4LOWCVSS 7.5fixed in phpmyadmin 4:4.6.3-1 (bookworm)2016
CVE-2016-5706 [HIGH] CVE-2016-5706: phpmyadmin - js/get_scripts.js.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.... js/get_scripts.js.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to cause a denial of service via a large array in the scripts parameter. Scope: local bookworm: resolved (fixed in 4:4.6.3-1) bullseye: resolved (fixed in 4:4.6.3-1) forky: resolved (fixed in 4:4.6.3-1) sid: resolved (fixed in 4:4.6.3-1)
debian
CVE-2006-6944P4MEDIUMCVSS 7.5fixed in phpmyadmin 4:2.9.1.1-2 (bookworm)2006
CVE-2006-6944 [HIGH] CVE-2006-6944: phpmyadmin - phpMyAdmin before 2.9.1.1 allows remote attackers to bypass Allow/Deny access ru... phpMyAdmin before 2.9.1.1 allows remote attackers to bypass Allow/Deny access rules that use IP addresses via false headers. Scope: local bookworm: resolved (fixed in 4:2.9.1.1-2) bullseye: resolved (fixed in 4:2.9.1.1-2) forky: resolved (fixed in 4:2.9.1.1-2) sid: resolved (fixed in 4:2.9.1.1-2) trixie: resolved (fixed in 4:2.9.1.1-2)
debian
CVE-2014-8959P3MEDIUMCVSS 6.5fixed in phpmyadmin 4:4.2.12-1 (bookworm)2014
CVE-2014-8959 [MEDIUM] CVE-2014-8959: phpmyadmin - Directory traversal vulnerability in libraries/gis/GIS_Factory.class.php in the ... Directory traversal vulnerability in libraries/gis/GIS_Factory.class.php in the GIS editor in phpMyAdmin 4.0.x before 4.0.10.6, 4.1.x before 4.1.14.7, and 4.2.x before 4.2.12 allows remote authenticated users to include and execute arbitrary local files via a crafted geometry-type parameter. Scope: local bookworm: resolved (fixed in 4:4.2.12-1) bullseye: resolved
debian
CVE-2016-6630P4MEDIUMCVSS 6.5fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6630 [MEDIUM] CVE-2016-6630: phpmyadmin - An issue was discovered in phpMyAdmin. An authenticated user can trigger a denia... An issue was discovered in phpMyAdmin. An authenticated user can trigger a denial-of-service (DoS) attack by entering a very long password at the change password dialog. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected. Scope: local bookworm: resolved (fixed in 4:4.6.4+dfsg1-1) bullseye:
debian
CVE-2016-6624P4MEDIUMCVSS 5.9fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6624 [MEDIUM] CVE-2016-6624: phpmyadmin - An issue was discovered in phpMyAdmin involving improper enforcement of the IP-b... An issue was discovered in phpMyAdmin involving improper enforcement of the IP-based authentication rules. When phpMyAdmin is used with IPv6 in a proxy server environment, and the proxy server is in the allowed range but the attacking computer is not allowed, this vulnerability can allow the attacking computer to connect despite the IP rules. All 4.6.x versions (
debian
CVE-2016-2039P4MEDIUMCVSS 5.3fixed in phpmyadmin 4:4.5.4-1 (bookworm)2016
CVE-2016-2039 [MEDIUM] CVE-2016-2039: phpmyadmin - libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4... libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value. Scope: local bookworm: resolved (fixed in 4:4.5.4-1) bullseye: resolved (fixed in 4:4.5.4-1) forky: resolved (fixed i
debian
CVE-2005-0567P4HIGHCVSS 7.5fixed in phpmyadmin 3:2.6.1-pl2-1 (bookworm)2005
CVE-2005-0567 [HIGH] CVE-2005-0567: phpmyadmin - Multiple PHP remote file inclusion vulnerabilities in phpMyAdmin 2.6.1 allow rem... Multiple PHP remote file inclusion vulnerabilities in phpMyAdmin 2.6.1 allow remote attackers to execute arbitrary PHP code by modifying the (1) theme parameter to phpmyadmin.css.php or (2) cfg[Server][extension] parameter to database_interface.lib.php to reference a URL on a remote web server that contains the code. Scope: local bookworm: resolved (fixed in 3:2.6.
debian
CVE-2017-1000014P4LOWCVSS 7.5fixed in phpmyadmin 4:4.6.6-1 (bookworm)2017
CVE-2017-1000014 [HIGH] CVE-2017-1000014: phpmyadmin - phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a DOS weakness in the table editi... phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a DOS weakness in the table editing functionality Scope: local bookworm: resolved (fixed in 4:4.6.6-1) bullseye: resolved (fixed in 4:4.6.6-1) forky: resolved (fixed in 4:4.6.6-1) sid: resolved (fixed in 4:4.6.6-1) trixie: resolved (fixed in 4:4.6.6-1)
debian
CVE-2009-1149P4HIGHCVSS 7.5fixed in phpmyadmin 4:3.1.3.1-1 (bookworm)2009
CVE-2009-1149 [HIGH] CVE-2009-1149: phpmyadmin - CRLF injection vulnerability in bs_disp_as_mime_type.php in the BLOB streaming f... CRLF injection vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the (1) c_type and possibly (2) file_type parameters. Scope: local bookworm: resolved (fixed in 4:3.1.3.1-1) bullseye: resolved (fixed in 4:3.1.3.
debian
CVE-2006-1804P4LOWCVSS 7.5fixed in phpmyadmin 4:2.8.1-1 (bookworm)2006
CVE-2006-1804 [HIGH] CVE-2006-1804: phpmyadmin - SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote att... SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to execute arbitrary SQL commands via the sql_query parameter. Scope: local bookworm: resolved (fixed in 4:2.8.1-1) bullseye: resolved (fixed in 4:2.8.1-1) forky: resolved (fixed in 4:2.8.1-1) sid: resolved (fixed in 4:2.8.1-1) trixie: resolved (fixed in 4:2.8.1-1)
debian
CVE-2011-0987P4MEDIUMCVSS 6.5fixed in phpmyadmin 4:3.3.9.2-1 (bookworm)2011
CVE-2011-0987 [MEDIUM] CVE-2011-0987: phpmyadmin - The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x... The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark. Scope: local bookworm: resolved (fixed in 4:3.3.9.2-1) bullseye: re
debian
CVE-2016-6618P4MEDIUMCVSS 6.5fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6618 [MEDIUM] CVE-2016-6618: phpmyadmin - An issue was discovered in phpMyAdmin. The transformation feature allows a user ... An issue was discovered in phpMyAdmin. The transformation feature allows a user to trigger a denial-of-service (DoS) attack against the server. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected. Scope: local bookworm: resolved (fixed in 4:4.6.4+dfsg1-1) bullseye: resolved (fixed in 4:4.6.
debian
CVE-2016-9860P4LOWCVSS 5.9fixed in phpmyadmin 4:4.6.5.1-1 (bookworm)2016
CVE-2016-9860 [MEDIUM] CVE-2016-9860: phpmyadmin - An issue was discovered in phpMyAdmin. An unauthenticated user can execute a den... An issue was discovered in phpMyAdmin. An unauthenticated user can execute a denial of service attack when phpMyAdmin is running with $cfg['AllowArbitraryServer']=true. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected. Scope: local bookworm: resolved (fixed in 4:4.6.5.1-1) bullseye: reso
debian
CVE-2025-24530P4MEDIUMCVSS 6.4fixed in phpmyadmin 4:5.2.1+dfsg-1+deb12u1 (bookworm)2025
CVE-2025-24530 [MEDIUM] CVE-2025-24530: phpmyadmin - An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has... An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the check tables feature. A crafted table or database name could be used for XSS. Scope: local bookworm: resolved (fixed in 4:5.2.1+dfsg-1+deb12u1) bullseye: resolved (fixed in 4:5.0.4+dfsg2-2+deb11u2) forky: resolved (fixed in 4:5.2.2-really5.2.2+20250121+dfsg-
debian
CVE-2016-6623P4MEDIUMCVSS 6.5fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6623 [MEDIUM] CVE-2016-6623: phpmyadmin - An issue was discovered in phpMyAdmin. An authorized user can cause a denial-of-... An issue was discovered in phpMyAdmin. An authorized user can cause a denial-of-service (DoS) attack on a server by passing large values to a loop. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected. Scope: local bookworm: resolved (fixed in 4:4.6.4+dfsg1-1) bullseye: resolved (fixed in 4:
debian
CVE-2007-5976P4LOWCVSS 6.5fixed in phpmyadmin 4:2.11.2.1-1 (bookworm)2007
CVE-2007-5976 [MEDIUM] CVE-2007-5976: phpmyadmin - SQL injection vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allow... SQL injection vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to execute arbitrary SQL commands via the db parameter. Scope: local bookworm: resolved (fixed in 4:2.11.2.1-1) bullseye: resolved (fixed in 4:2.11.2.1-1) forky: resolved (fixed in 4:2.11.2.1-1) sid: resolved (fixed in 4:2.1
debian
CVE-2011-2508P4MEDIUMCVSS 6.0fixed in phpmyadmin 4:3.4.3.1-1 (bookworm)2011
CVE-2011-2508 [MEDIUM] CVE-2011-2508: phpmyadmin - Directory traversal vulnerability in libraries/display_tbl.lib.php in phpMyAdmin... Directory traversal vulnerability in libraries/display_tbl.lib.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1, when a certain MIME transformation feature is enabled, allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in a GLOBALS[mime_map][$meta->name][transformation] parameter. Scope: local bookworm:
debian
Debian Phpmyadmin vulnerabilities | cvebase