cbcvebase.

Debian Phpmyadmin vulnerabilities

253 known vulnerabilities affecting debian/phpmyadmin.

Total CVEs
253
CISA KEV
1
actively exploited
Public exploits
34
Exploited in wild
3
Severity breakdown
CRITICAL18HIGH27MEDIUM95LOW113

Vulnerabilities

Page 7 of 13
CVE-2015-2206P4LOWCVSS 5.0fixed in phpmyadmin 4:4.4.4-1 (bookworm)2015
CVE-2015-2206 [MEDIUM] CVE-2015-2206: phpmyadmin - libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before ... libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of craf
debian
CVE-2016-9858P4LOWCVSS 5.3fixed in phpmyadmin 4:4.6.5.1-1 (bookworm)2016
CVE-2016-9858 [MEDIUM] CVE-2016-9858: phpmyadmin - An issue was discovered in phpMyAdmin. With a crafted request parameter value it... An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in saved searches feature. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected. Scope: local bookworm: resolved (fixed in 4:4.6.5.1-1) bullseye: resolved (fixe
debian
CVE-2016-9859P4LOWCVSS 5.3fixed in phpmyadmin 4:4.6.5.1-1 (bookworm)2016
CVE-2016-9859 [MEDIUM] CVE-2016-9859: phpmyadmin - An issue was discovered in phpMyAdmin. With a crafted request parameter value it... An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in import feature. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected. Scope: local bookworm: resolved (fixed in 4:4.6.5.1-1) bullseye: resolved (fixed in 4:4
debian
CVE-2016-9851P4LOWCVSS 5.3fixed in phpmyadmin 4:4.6.5.1-1 (bookworm)2016
CVE-2016-9851 [MEDIUM] CVE-2016-9851: phpmyadmin - An issue was discovered in phpMyAdmin. With a crafted request parameter value it... An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to bypass the logout timeout. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. Scope: local bookworm: resolved (fixed in 4:4.6.5.1-1) bullseye: resolved (fixed in 4:4.6.5.1-1) forky: resolved (fixed in 4:4.6.5.1-1) sid: resolved (f
debian
CVE-2016-6627P4MEDIUMCVSS 5.3fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6627 [MEDIUM] CVE-2016-6627: phpmyadmin - An issue was discovered in phpMyAdmin. An attacker can determine the phpMyAdmin ... An issue was discovered in phpMyAdmin. An attacker can determine the phpMyAdmin host location through the file url.php. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected. Scope: local bookworm: resolved (fixed in 4:4.6.4+dfsg1-1) bullseye: resolved (fixed in 4:4.6.4+dfsg1-1) forky: resolv
debian
CVE-2016-9848P4LOWCVSS 5.3fixed in phpmyadmin 4:4.6.5.1-1 (bookworm)2016
CVE-2016-9848 [MEDIUM] CVE-2016-9848: phpmyadmin - An issue was discovered in phpMyAdmin. phpinfo (phpinfo.php) shows PHP informati... An issue was discovered in phpMyAdmin. phpinfo (phpinfo.php) shows PHP information including values of HttpOnly cookies. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected. Scope: local bookworm: resolved (fixed in 4:4.6.5.1-1) bullseye: resolved (fixed in 4:4.6.5.1-1) forky: resolved (fix
debian
CVE-2016-2560P4LOWCVSS 6.1fixed in phpmyadmin 4:4.5.5.1-1 (bookworm)2016
CVE-2016-2560 [MEDIUM] CVE-2016-2560: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4... Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.15, 4.4.x before 4.4.15.5, and 4.5.x before 4.5.5.1 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted Host HTTP header, related to libraries/Config.class.php; (2) crafted JSON data, related to file_echo.php; (3) a crafted SQL query, related to js/fu
debian
CVE-2005-4349P4LOWCVSS 6.3fixed in phpmyadmin 4:3.2.0-1 (bookworm)2005
CVE-2005-4349 [MEDIUM] CVE-2005-4349: phpmyadmin - SQL injection vulnerability in server_privileges.php in phpMyAdmin 2.7.0 allows ... SQL injection vulnerability in server_privileges.php in phpMyAdmin 2.7.0 allows remote authenticated users to execute arbitrary SQL commands via the (1) dbname and (2) checkprivs parameters. NOTE: the vendor and a third party have disputed this issue, saying that the main task of the program is to support query execution by authenticated users, and no external at
debian
CVE-2018-12581P4LOWCVSS 6.1fixed in phpmyadmin 4:4.9.1+dfsg1-2 (bookworm)2018
CVE-2018-12581 [MEDIUM] CVE-2018-12581: phpmyadmin - An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cro... An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted database name to trigger an XSS attack when that database is referenced from the Designer feature. Scope: local bookworm: resolved (fixed in 4:4.9.1+dfsg1-2) bullseye: resolved (fixed in 4:4.9.1+dfsg1
debian
CVE-2016-5730P4LOWCVSS 5.3fixed in phpmyadmin 4:4.6.3-1 (bookworm)2016
CVE-2016-5730 [MEDIUM] CVE-2016-5730: phpmyadmin - phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3... phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to obtain sensitive information via vectors involving (1) an array value to FormDisplay.php, (2) incorrect data to validate.php, (3) unexpected data to Validator.php, (4) a missing config directory during setup, or (5) an incorrect OpenID identifier data type,
debian
CVE-2005-3300P4HIGHCVSS 5.0fixed in phpmyadmin 4:2.6.4-pl3-1 (bookworm)2005
CVE-2005-3300 [MEDIUM] CVE-2005-3300: phpmyadmin - The register_globals emulation layer in grab_globals.php for phpMyAdmin before 2... The register_globals emulation layer in grab_globals.php for phpMyAdmin before 2.6.4-pl3 does not perform safety checks on values in the _FILES array for uploaded files, which allows remote attackers to include arbitrary files by using direct requests to library scripts that do not use grab_globals.php, then modifying certain configuration values for the theme. S
debian
CVE-2016-9856P4LOWCVSS 5.4fixed in phpmyadmin 4:4.6.5.1-1 (bookworm)2016
CVE-2016-9856 [MEDIUM] CVE-2016-9856: phpmyadmin - An XSS issue was discovered in phpMyAdmin because of an improper fix for CVE-201... An XSS issue was discovered in phpMyAdmin because of an improper fix for CVE-2016-2559 in PMASA-2016-10. This issue is resolved by using a copy of a hash to avoid a race condition. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected. Scope: local bookworm: resolved (fixed in 4:4.6.5.1-1) bu
debian
CVE-2009-1148P4MEDIUMCVSS 5.0fixed in phpmyadmin 4:3.1.3.1-1 (bookworm)2009
CVE-2009-1148 [MEDIUM] CVE-2009-1148: phpmyadmin - Directory traversal vulnerability in bs_disp_as_mime_type.php in the BLOB stream... Directory traversal vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to read arbitrary files via directory traversal sequences in the file_path parameter ($filename variable). Scope: local bookworm: resolved (fixed in 4:3.1.3.1-1) bullseye: resolved (fixed in 4:3.1.3.1-1) forky: resolved
debian
CVE-2016-5733P4MEDIUMCVSS 6.1fixed in phpmyadmin 4:4.6.3-1 (bookworm)2016
CVE-2016-5733 [MEDIUM] CVE-2016-5733: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4... Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a crafted table name that is mishandled during privilege checking in table_row.phtml, (2) a crafted mysqld log_bin directive that is mishandl
debian
CVE-2017-1000015P4LOWCVSS 6.1fixed in phpmyadmin 4:4.6.6-1 (bookworm)2017
CVE-2017-1000015 [MEDIUM] CVE-2017-1000015: phpmyadmin - phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a CSS injection attack through cr... phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a CSS injection attack through crafted cookie parameters Scope: local bookworm: resolved (fixed in 4:4.6.6-1) bullseye: resolved (fixed in 4:4.6.6-1) forky: resolved (fixed in 4:4.6.6-1) sid: resolved (fixed in 4:4.6.6-1) trixie: resolved (fixed in 4:4.6.6-1)
debian
CVE-2016-9853P4LOWCVSS 5.3fixed in phpmyadmin 4:4.6.5.1-1 (bookworm)2016
CVE-2016-9853 [MEDIUM] CVE-2016-9853: phpmyadmin - An issue was discovered in phpMyAdmin. By calling some scripts that are part of ... An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directo
debian
CVE-2016-9855P4LOWCVSS 5.3fixed in phpmyadmin 4:4.6.5.1-1 (bookworm)2016
CVE-2016-9855 [MEDIUM] CVE-2016-9855: phpmyadmin - An issue was discovered in phpMyAdmin. By calling some scripts that are part of ... An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directo
debian
CVE-2016-9852P4LOWCVSS 5.3fixed in phpmyadmin 4:4.6.5.1-1 (bookworm)2016
CVE-2016-9852 [MEDIUM] CVE-2016-9852: phpmyadmin - An issue was discovered in phpMyAdmin. By calling some scripts that are part of ... An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directo
debian
CVE-2016-9854P4LOWCVSS 5.3fixed in phpmyadmin 4:4.6.5.1-1 (bookworm)2016
CVE-2016-9854 [MEDIUM] CVE-2016-9854: phpmyadmin - An issue was discovered in phpMyAdmin. By calling some scripts that are part of ... An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directo
debian
CVE-2015-7873P4LOWCVSS 5.0fixed in phpmyadmin 4:4.5.1-1 (bookworm)2015
CVE-2015-7873 [MEDIUM] CVE-2015-7873: phpmyadmin - The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x... The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter. Scope: local bookworm: resolved (fixed in 4:4.5.1-1) bullseye: resolved (fixed in 4:4.5.1-1) forky: resolved (fixed in 4:4.5.1-1) sid: resolved (fixed in 4:4.5.1-1) trixie: resolved (fixed in 4:4.5.1-1)
debian