#Vulnerabilities 271
Date Id Summary Products Score Patch Annotated
2005-12-19 CVE-2005-4349 SQL injection vulnerability in server_privileges.php in phpMyAdmin 2.7.0 allows remote authenticated users to execute arbitrary SQL commands via the (1) dbname and (2) checkprivs parameters. NOTE: the vendor and a third party have disputed this issue, saying that the main task of the program is to support query execution by authenticated users, and no external attack scenario exists without an auto-login configuration. Thus it is likely that this issue will be REJECTED. However, a closely... Phpmyadmin N/A
2013-04-16 CVE-2013-1937 Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might allow remote attackers to inject arbitrary web script or HTML via the (1) visualizationSettings[width] or (2) visualizationSettings[height] parameter. NOTE: a third party reports that this is "not exploitable. Phpmyadmin 6.1
2020-03-31 CVE-2020-11441 phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable. Phpmyadmin 6.1
2020-11-04 CVE-2020-22278 phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents. Phpmyadmin 8.8
2008-03-31 CVE-2008-1567 phpMyAdmin before stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information. Debian_linux, Fedora, Opensuse, Phpmyadmin 5.5
2011-11-17 CVE-2011-4107 The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before and 3.3.x before allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack. Debian_linux, Fedora, Phpmyadmin 6.5
2022-01-22 CVE-2022-23807 An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances. Phpmyadmin 4.3
2022-01-22 CVE-2022-23808 An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection. Phpmyadmin 6.1
2022-03-10 CVE-2022-0813 PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section. Phpmyadmin 7.5
2010-08-24 CVE-2010-3055 The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before does not properly restrict key names in its output file, which allows remote attackers to execute arbitrary PHP code via a crafted POST request. Phpmyadmin N/A