cbcvebase.

Debian Phpmyadmin vulnerabilities

253 known vulnerabilities affecting debian/phpmyadmin.

Total CVEs
253
CISA KEV
1
actively exploited
Public exploits
34
Exploited in wild
3
Severity breakdown
CRITICAL18HIGH27MEDIUM95LOW113

Vulnerabilities

Page 9 of 13
CVE-2016-2559P4LOWCVSS 5.4fixed in phpmyadmin 4:4.5.5.1-1 (bookworm)2016
CVE-2016-2559 [MEDIUM] CVE-2016-2559: phpmyadmin - Cross-site scripting (XSS) vulnerability in the format function in libraries/sql... Cross-site scripting (XSS) vulnerability in the format function in libraries/sql-parser/src/Utils/Error.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted query. Scope: local bookworm: resolved (fixed in 4:4.5.5.1-1) bullseye: resolved (fixed in 4:4.5.5.1-1) forky: resolv
debian
CVE-2009-4605P4MEDIUMCVSS 5.0fixed in phpmyadmin 4:3.2.4-1 (bookworm)2009
CVE-2009-4605 [MEDIUM] CVE-2009-4605: phpmyadmin - scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 cal... scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors. Scope: local bookworm: resolved (fixed in 4:3.2.4-1) bullseye: resolved (fixed i
debian
CVE-2006-5117P4LOWCVSS 5.0fixed in phpmyadmin 4:2.9.0.2-0.1 (bookworm)2006
CVE-2006-5117 [MEDIUM] CVE-2006-5117: phpmyadmin - phpMyAdmin before 2.9.1-rc1 has a libraries directory under the web document roo... phpMyAdmin before 2.9.1-rc1 has a libraries directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via direct requests for certain files. Scope: local bookworm: resolved (fixed in 4:2.9.0.2-0.1) bullseye: resolved (fixed in 4:2.9.0.2-0.1) forky: resolved (fixed in 4:2.9.0.2-0.1) sid: r
debian
CVE-2016-6625P4LOWCVSS 4.3fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6625 [MEDIUM] CVE-2016-6625: phpmyadmin - An issue was discovered in phpMyAdmin. An attacker can determine whether a user ... An issue was discovered in phpMyAdmin. An attacker can determine whether a user is logged in to phpMyAdmin. The user's session, username, and password are not compromised by this vulnerability. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected. Scope: local bookworm: resolved (fixed in 4:
debian
CVE-2022-23807P4LOWCVSS 4.3fixed in phpmyadmin 4:5.1.3+dfsg1-1 (bookworm)2022
CVE-2022-23807 [MEDIUM] CVE-2022-23807: phpmyadmin - An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A v... An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances. Scope: local bookworm: resolved (fixed in 4:5.1.3+dfsg1-1) bullseye: open forky: resolved (fixed in 4:5.1.3+dfsg1-1) sid: resolved (fixed
debian
CVE-2016-2038P4LOWCVSS 5.3fixed in phpmyadmin 4:4.5.4-1 (bookworm)2016
CVE-2016-2038 [MEDIUM] CVE-2016-2038: phpmyadmin - phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4... phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message. Scope: local bookworm: resolved (fixed in 4:4.5.4-1) bullseye: resolved (fixed in 4:4.5.4-1) forky: resolved (fixed in 4:4.5.4-1) sid: resolved (fixed in 4:
debian
CVE-2016-2043P4MEDIUMCVSS 5.4fixed in phpmyadmin 4:4.5.4-1 (bookworm)2016
CVE-2016-2043 [MEDIUM] CVE-2016-2043: phpmyadmin - Cross-site scripting (XSS) vulnerability in the goToFinish1NF function in js/nor... Cross-site scripting (XSS) vulnerability in the goToFinish1NF function in js/normalization.js in phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a table name to the normalization page. Scope: local bookworm: resolved (fixed in 4:4.5.4-1) bullseye: resolved (fixed in 4:4.5.4-1) fo
debian
CVE-2008-1149P4LOWCVSS 5.1fixed in phpmyadmin 4:2.11.5-1 (bookworm)2008
CVE-2008-1149 [MEDIUM] CVE-2008-1149: phpmyadmin - phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of... phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies. Scope: local bookworm: resolved (fixed in 4:2.11.5-1) bullseye: resolved (fixed in 4:2.11.5-1) f
debian
CVE-2006-5116P4LOWCVSS 9.3fixed in phpmyadmin 4:2.9.0.2-0.1 (bookworm)2006
CVE-2006-5116 [CRITICAL] CVE-2006-5116: phpmyadmin - Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyAdmin before ... Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyAdmin before 2.9.1-rc1 allow remote attackers to perform unauthorized actions as another user by (1) directly setting a token in the URL though dynamic variable evaluation and (2) unsetting arbitrary variables via the _REQUEST array, related to (a) libraries/common.lib.php, (b) session.inc.php,
debian
CVE-2009-3696P4MEDIUMCVSS 4.3fixed in phpmyadmin 4:3.2.2.1-1 (bookworm)2009
CVE-2009-3696 [MEDIUM] CVE-2009-3696: phpmyadmin - Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.11.x before 2.11.9.6 an... Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name for a MySQL table. Scope: local bookworm: resolved (fixed in 4:3.2.2.1-1) bullseye: resolved (fixed in 4:3.2.2.1-1) forky: resolved (fixed in 4:3.2.2.1-1) sid: resolved (fixed in 4:3
debian
CVE-2010-4329P4MEDIUMCVSS 4.3fixed in phpmyadmin 4:3.3.7-2 (bookworm)2010
CVE-2010-4329 [MEDIUM] CVE-2010-4329: phpmyadmin - Cross-site scripting (XSS) vulnerability in the PMA_linkOrButton function in lib... Cross-site scripting (XSS) vulnerability in the PMA_linkOrButton function in libraries/common.lib.php in the database (db) search script in phpMyAdmin 2.11.x before 2.11.11.1 and 3.x before 3.3.8.1 allows remote attackers to inject arbitrary web script or HTML via a crafted request. Scope: local bookworm: resolved (fixed in 4:3.3.7-2) bullseye: resolved (fixed in
debian
CVE-2007-2245P4LOWCVSS 6.8fixed in phpmyadmin 4:2.10.1-1 (bookworm)2007
CVE-2007-2245 [MEDIUM] CVE-2007-2245: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1.... Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the fieldkey parameter to browse_foreigners.php or (2) certain input to the PMA_sanitize function. Scope: local bookworm: resolved (fixed in 4:2.10.1-1) bullseye: resolved (fixed in 4:2.10.1-1) forky: resolved (fi
debian
CVE-2014-6300P4MEDIUMCVSS 4.3fixed in phpmyadmin 4:4.2.8.1-1 (bookworm)2014
CVE-2014-6300 [MEDIUM] CVE-2014-6300: phpmyadmin - Cross-site scripting (XSS) vulnerability in the micro history implementation in ... Cross-site scripting (XSS) vulnerability in the micro history implementation in phpMyAdmin 4.0.x before 4.0.10.3, 4.1.x before 4.1.14.4, and 4.2.x before 4.2.8.1 allows remote attackers to inject arbitrary web script or HTML, and consequently conduct a cross-site request forgery (CSRF) attack to create a root account, via a crafted URL, related to js/ajax.js. Sco
debian
CVE-2016-4412P4MEDIUMCVSS 4.4fixed in phpmyadmin 4:4.1.7-1 (bookworm)2016
CVE-2016-4412 [MEDIUM] CVE-2016-4412: phpmyadmin - An issue was discovered in phpMyAdmin. A user can be tricked into following a li... An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token. All 4.0.x versions (prior to 4.0.10.16) are affected. Scope: local bookworm: resolved (fixed in 4:4.1.7-1) bullseye: resolved (fixed in
debian
CVE-2006-3388P4LOWCVSS 5.8fixed in phpmyadmin 4:2.8.2-0.1 (bookworm)2006
CVE-2006-3388 [MEDIUM] CVE-2006-3388: phpmyadmin - Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.8.2 allows remot... Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via the table parameter. Scope: local bookworm: resolved (fixed in 4:2.8.2-0.1) bullseye: resolved (fixed in 4:2.8.2-0.1) forky: resolved (fixed in 4:2.8.2-0.1) sid: resolved (fixed in 4:2.8.2-0.1) trixie: resolved (fixed in 4:2.8.2-0
debian
CVE-2015-8669P4LOWCVSS 5.3fixed in phpmyadmin 4:4.5.3.1-1 (bookworm)2015
CVE-2015-8669 [MEDIUM] CVE-2015-8669: phpmyadmin - libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x be... libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message. Scope: local bookworm: resolved (fixed in 4:4.5.3.1-1) bullseye: resolved (fixed in 4:4.5.3.1-1) forky: resolved (fix
debian
CVE-2005-3621P4MEDIUMCVSS 5.0fixed in phpmyadmin 4:2.6.4-pl4-1 (bookworm)2005
CVE-2005-3621 [MEDIUM] CVE-2005-3621: phpmyadmin - CRLF injection vulnerability in phpMyAdmin before 2.6.4-pl4 allows remote attack... CRLF injection vulnerability in phpMyAdmin before 2.6.4-pl4 allows remote attackers to conduct HTTP response splitting attacks via unspecified scripts. Scope: local bookworm: resolved (fixed in 4:2.6.4-pl4-1) bullseye: resolved (fixed in 4:2.6.4-pl4-1) forky: resolved (fixed in 4:2.6.4-pl4-1) sid: resolved (fixed in 4:2.6.4-pl4-1) trixie: resolved (fixed in 4:2.6
debian
CVE-2010-3056P4MEDIUMCVSS 4.3fixed in phpmyadmin 4:3.3.5.1-1 (bookworm)2010
CVE-2010-3056 [MEDIUM] CVE-2010-3056: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.11.x before ... Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.11.x before 2.11.10.1 and 3.x before 3.3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) db_search.php, (2) db_sql.php, (3) db_structure.php, (4) js/messages.php, (5) libraries/common.lib.php, (6) libraries/database_interface.lib.php, (7) libraries/dbi
debian
CVE-2007-1325P4LOWCVSS 2.1fixed in phpmyadmin 4:2.10.0.2-1 (bookworm)2007
CVE-2007-1325 [LOW] CVE-2007-1325: phpmyadmin - The PMA_ArrayWalkRecursive function in libraries/common.lib.php in phpMyAdmin be... The PMA_ArrayWalkRecursive function in libraries/common.lib.php in phpMyAdmin before 2.10.0.2 does not limit recursion on arrays provided by users, which allows context-dependent attackers to cause a denial of service (web server crash) via an array with many dimensions. NOTE: it could be argued that this vulnerability is caused by a problem in PHP (CVE-2006-1549) a
debian
CVE-2011-4634P4LOWCVSS 4.3fixed in phpmyadmin 4:3.4.8-1 (bookworm)2011
CVE-2011-4634 [MEDIUM] CVE-2011-4634: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3... Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.8 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted database name, related to the Database Synchronize panel; (2) a crafted database name, related to the Database rename panel; (3) a crafted SQL query, related to the table overview panel; (4) a crafted
debian
Debian Phpmyadmin vulnerabilities | cvebase