<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – phpMyAdmin (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/phpmyadmin.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/phpmyadmin-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – phpMyAdmin (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:51 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-41930 – Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41930</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41930</guid>
    <pubDate>Wed, 06 May 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41930</strong></p>
  <p>Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configuration that allows unauthenticated attackers to access the bundled phpMyAdmin container with pre-configured database credentials. Attackers can connect to the phpMyAdmin port to gain unrestricted read and write access to the entire Vvveb database, including administrator password…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41930">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37116 – GUnet OpenEclass 1.7.3 includes phpMyAdmin 2.10.0.2 by default, which allows rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37116</guid>
    <pubDate>Tue, 03 Feb 2026 18:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37116</strong></p>
  <p>GUnet OpenEclass 1.7.3 includes phpMyAdmin 2.10.0.2 by default, which allows remote logins. Attackers with access to the platform can remotely access phpMyAdmin and, after uploading a shell, view the config.php file to obtain the MySQL password, leading to full database compromise.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-46188 – SourceCodester Client Database Management System 1.0 is vulnerable to SQL Inject...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46188</guid>
    <pubDate>Fri, 09 May 2025 16:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-46188</strong></p>
  <p>SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-22452 – SQL Injection vulnerability in function getTableCreationQuery in CreateAddField...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-22452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-22452</guid>
    <pubDate>Thu, 26 Jan 2023 21:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-22452</strong></p>
  <p>SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-26939 – An information disclosure issue exists in henriquedornas 5.2.17 because an attac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26939</guid>
    <pubDate>Wed, 10 Feb 2021 18:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-26939</strong></p>
  <p>An information disclosure issue exists in henriquedornas 5.2.17 because an attacker can dump phpMyAdmin SQL content. NOTE: third parties report that this is a site-specific problem</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-22278 – phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vend...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-22278</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-22278</guid>
    <pubDate>Wed, 04 Nov 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-22278</strong></p>
  <p>phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1236</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22278">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-26935 – An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26935</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26935</guid>
    <pubDate>Sat, 10 Oct 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-26935</strong></p>
  <p>An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26935">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10802 – In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10802</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10802</guid>
    <pubDate>Sun, 22 Mar 2020 05:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10802</strong></p>
  <p>In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/classes/Controllers/Table/TableSearchController.php. An attacker can generate a crafted database or table name. The attack can be performed if a user attempts certain search operatio…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10802">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10804 – In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10804</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10804</guid>
    <pubDate>Sun, 22 Mar 2020 04:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10804</strong></p>
  <p>In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A malicious user with access to the server could create a crafted username, and then trick the victim into performing specific actions with that user account (such as editing its privi…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10804">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-4454 – WordPress Portable phpMyAdmin Plugin 1.4.1 has Multiple Security Bypass Vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4454</guid>
    <pubDate>Tue, 18 Feb 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-4454</strong></p>
  <p>WordPress Portable phpMyAdmin Plugin 1.4.1 has Multiple Security Bypass Vulnerabilities</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-4462 – WordPress Portable phpMyAdmin Plugin has an authentication bypass vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4462</guid>
    <pubDate>Mon, 27 Jan 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-4462</strong></p>
  <p>WordPress Portable phpMyAdmin Plugin has an authentication bypass vulnerability</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-5504 – In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5504</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5504</guid>
    <pubDate>Thu, 09 Jan 2020 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-5504</strong></p>
  <p>In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5504">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-19617 – phpMyAdmin before 4.9.2 does not escape certain Git information, related to libr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19617</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19617</guid>
    <pubDate>Fri, 06 Dec 2019 03:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-19617</strong></p>
  <p>phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19617">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-18622 – An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table nam...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18622</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18622</guid>
    <pubDate>Fri, 22 Nov 2019 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-18622</strong></p>
  <p>An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18622">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-11768 – An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was report...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11768</guid>
    <pubDate>Wed, 05 Jun 2019 05:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-11768</strong></p>
  <p>An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an SQL injection attack through the designer feature.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-6798 – An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-6798</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-6798</guid>
    <pubDate>Sat, 26 Jan 2019 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-6798</strong></p>
  <p>An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can be used to trigger a SQL injection attack through the designer feature.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-6798">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-19969 – phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19969</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19969</guid>
    <pubDate>Tue, 11 Dec 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-19969</strong></p>
  <p>phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is possible to perform harmful SQL operations such as renaming databases, creating new tables/routines, deleting designer pages, adding/deleting users, updating user passwords, killing SQL processes, etc.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19969">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-12613 – An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-12613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-12613</guid>
    <pubDate>Thu, 21 Jun 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-12613</strong></p>
  <p>An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages. An attacker must be authenticated, except in the "$cfg['AllowArbitraryServer'] = true" case (where an attack…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-12613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-18264 – An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18264</guid>
    <pubDate>Tue, 01 May 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-18264</strong></p>
  <p>An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0.10.20, 4.4.x, 4.6.x, and 4.7.0 prereleases. The restrictions caused by $cfg['Servers'][$i]['AllowNoPassword'] = false are bypassed under certain PHP versions (e.g., version 5). This can allow the login of users who have no password set even if the administrator has set $cfg['Servers'][$i]['AllowNoPassword'] to false…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-10188 – phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10188</guid>
    <pubDate>Thu, 19 Apr 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-10188</strong></p>
  <p>phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations.js, libraries/classes/Operations.php, and sql.php.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1000499 – phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weak...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000499</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000499</guid>
    <pubDate>Wed, 03 Jan 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1000499</strong></p>
  <p>phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000499">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1000018 – phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000018</guid>
    <pubDate>Mon, 17 Jul 2017 13:18:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1000018</strong></p>
  <p>phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication status by using a specially crafted table name</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1000017 – phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000017</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000017</guid>
    <pubDate>Mon, 17 Jul 2017 13:18:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1000017</strong></p>
  <p>phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to an arbitrary MySQL server</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000017">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1000014 – phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a DOS weakness in the table editi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000014</guid>
    <pubDate>Mon, 17 Jul 2017 13:18:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1000014</strong></p>
  <p>phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a DOS weakness in the table editing functionality</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6621 – The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6621</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6621</guid>
    <pubDate>Tue, 31 Jan 2017 19:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6621</strong></p>
  <p>The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6621">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-9866 – An issue was discovered in phpMyAdmin. When the arg_separator is different from ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9866</guid>
    <pubDate>Sun, 11 Dec 2016 03:00:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-9866</strong></p>
  <p>An issue was discovered in phpMyAdmin. When the arg_separator is different from its default & value, the CSRF token was not properly stripped from the return URL of the preference import action. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-9865 – An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9865</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9865</guid>
    <pubDate>Sun, 11 Dec 2016 03:00:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-9865</strong></p>
  <p>An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9865">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9864 – An issue was discovered in phpMyAdmin. With a crafted username or a table name, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9864</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9864</guid>
    <pubDate>Sun, 11 Dec 2016 03:00:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9864</strong></p>
  <p>An issue was discovered in phpMyAdmin. With a crafted username or a table name, it was possible to inject SQL statements in the tracking functionality that would run with the privileges of the control user. This gives read and write access to the tables of the configuration storage database, and if the control user has the necessary privileges, read access to some tables of the MySQL database. Al…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9864">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9863 – An issue was discovered in phpMyAdmin. With a very large request to table partit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9863</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9863</guid>
    <pubDate>Sun, 11 Dec 2016 03:00:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9863</strong></p>
  <p>An issue was discovered in phpMyAdmin. With a very large request to table partitioning function, it is possible to invoke a Denial of Service (DoS) attack. All 4.6.x versions (prior to 4.6.5) are affected.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9863">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9862 – An issue was discovered in phpMyAdmin. With a crafted login request it is possib...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9862</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9862</guid>
    <pubDate>Sun, 11 Dec 2016 03:00:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9862</strong></p>
  <p>An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9862">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9861 – An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9861</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9861</guid>
    <pubDate>Sun, 11 Dec 2016 03:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9861</strong></p>
  <p>An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it was possible to bypass the URL white-list protection. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9861">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-9849 – An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9849</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-9849</strong></p>
  <p>An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restriction ($cfg['Servers'][$i]['AllowRoot']) and deny rules for username by using Null Byte in the username. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6633 – An issue was discovered in phpMyAdmin. phpMyAdmin can be used to trigger a remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6633</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6633</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6633</strong></p>
  <p>An issue was discovered in phpMyAdmin. phpMyAdmin can be used to trigger a remote code execution attack against certain PHP installations that are running with the dbase extension. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6633">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6631 – An issue was discovered in phpMyAdmin. A user can execute a remote code executio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6631</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6631</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6631</strong></p>
  <p>An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmin is being run as a CGI application. Under certain server configurations, a user can pass a query string which is executed as a command-line argument by the file generator_plugin.sh. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (pri…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6631">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-6629 – An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6629</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-6629</strong></p>
  <p>An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive. An attacker could reuse certain cookie values in a way of bypassing the servers defined by ArbitraryServerRegexp. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-6620 – An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserializ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6620</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6620</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-6620</strong></p>
  <p>An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. The unserialization can result in code execution because of the interaction with object instantiation and autoloading. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6620">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6619 – An issue was discovered in phpMyAdmin. In the user interface preference feature,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6619</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6619</strong></p>
  <p>An issue was discovered in phpMyAdmin. In the user interface preference feature, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6617 – An issue was discovered in phpMyAdmin. A specially crafted database and/or table...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6617</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6617</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6617</strong></p>
  <p>An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4) are affected.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6617">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6616 – An issue was discovered in phpMyAdmin. In the "User group" and "Designer" featur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6616</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6616</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6616</strong></p>
  <p>An issue was discovered in phpMyAdmin. In the "User group" and "Designer" features, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4) and 4.4.x versions (prior to 4.4.15.8) are affected.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6616">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6611 – An issue was discovered in phpMyAdmin. A specially crafted database and/or table...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6611</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6611</strong></p>
  <p>An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6609 – An issue was discovered in phpMyAdmin. A specially crafted database name could b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6609</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6609</strong></p>
  <p>An issue was discovered in phpMyAdmin. A specially crafted database name could be used to run arbitrary PHP commands through the array export feature. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6606 – An issue was discovered in cookie encryption in phpMyAdmin. The decryption of th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6606</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6606</strong></p>
  <p>An issue was discovered in cookie encryption in phpMyAdmin. The decryption of the username/password is vulnerable to a padding oracle attack. This can allow an attacker who has access to a user's browser cookie file to decrypt the username and password. Furthermore, the same initialization vector (IV) is used to hash the username and password stored in the phpMyAdmin cookie. If a user has the sam…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-5739 – The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5739</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5739</guid>
    <pubDate>Sun, 03 Jul 2016 01:59:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-5739</strong></p>
  <p>The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not use the no-referrer Content Security Policy (CSP) protection mechanism, which makes it easier for remote attackers to conduct CSRF attacks by reading an authentication token in a Referer header, related to libraries/Header.php.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5739">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-5734 – phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5734</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5734</guid>
    <pubDate>Sun, 03 Jul 2016 01:59:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-5734</strong></p>
  <p>phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_replace e (aka eval) modifier, which might allow remote attackers to execute arbitrary PHP code via a crafted string, as demonstrated by the table search-and-replace implementation.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5734">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-5706 – js/get_scripts.js.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5706</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5706</guid>
    <pubDate>Sun, 03 Jul 2016 01:59:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-5706</strong></p>
  <p>js/get_scripts.js.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to cause a denial of service via a large array in the scripts parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5706">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-5703 – SQL injection vulnerability in libraries/central_columns.lib.php in phpMyAdmin 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5703</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5703</guid>
    <pubDate>Sun, 03 Jul 2016 01:59:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-5703</strong></p>
  <p>SQL injection vulnerability in libraries/central_columns.lib.php in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allows remote attackers to execute arbitrary SQL commands via a crafted database name that is mishandled in a central column query.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5703">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-2041 – libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-2041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-2041</guid>
    <pubDate>Sat, 20 Feb 2016 01:59:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-2041</strong></p>
  <p>libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to bypass intended access restrictions by measuring time differences.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-2041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-1927 – The suggestPassword function in js/functions.js in phpMyAdmin 4.0.x before 4.0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-1927</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-1927</guid>
    <pubDate>Sat, 20 Feb 2016 01:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-1927</strong></p>
  <p>The suggestPassword function in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 relies on the Math.random JavaScript function, which makes it easier for remote attackers to guess passwords via a brute-force approach.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-1927">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-5469 – The Portable phpMyAdmin plugin before 1.3.1 for WordPress allows remote attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5469</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5469</guid>
    <pubDate>Thu, 20 Dec 2012 12:02:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-5469</strong></p>
  <p>The Portable phpMyAdmin plugin before 1.3.1 for WordPress allows remote attackers to bypass authentication and obtain phpMyAdmin console access via a direct request to wp-content/plugins/portable-phpmyadmin/wp-pma-mod.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5469">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-5159 – phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5159</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5159</guid>
    <pubDate>Tue, 25 Sep 2012 22:55:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-5159</strong></p>
  <p>phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_sync.php, which allows remote attackers to execute arbitrary PHP code via an eval injection attack.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5159">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-2506 – setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2506</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2506</guid>
    <pubDate>Thu, 14 Jul 2011 23:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-2506</strong></p>
  <p>setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restrict the presence of comment closing delimiters, which allows remote attackers to conduct static code injection attacks by leveraging the ability to modify the SESSION superglobal array.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2506">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-3055 – The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-3055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-3055</guid>
    <pubDate>Tue, 24 Aug 2010 20:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-3055</strong></p>
  <p>The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before 2.11.10.1 does not properly restrict key names in its output file, which allows remote attackers to execute arbitrary PHP code via a crafted POST request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-3055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-7252 – libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-7252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-7252</guid>
    <pubDate>Tue, 19 Jan 2010 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-7252</strong></p>
  <p>libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and attack vectors.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-7252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-7251 – libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 creates a temporary...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-7251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-7251</guid>
    <pubDate>Tue, 19 Jan 2010 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-7251</strong></p>
  <p>libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 creates a temporary directory with 0777 permissions, which has unknown impact and attack vectors.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-7251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-3697 – SQL injection vulnerability in the PDF schema generator functionality in phpMyAd...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-3697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-3697</guid>
    <pubDate>Fri, 16 Oct 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-3697</strong></p>
  <p>SQL injection vulnerability in the PDF schema generator functionality in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified interface parameters.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-3697">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-1285 – Static code injection vulnerability in the getConfigFile function in setup/lib/C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1285</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1285</guid>
    <pubDate>Thu, 16 Apr 2009 15:12:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-1285</strong></p>
  <p>Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP code into configuration files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1285">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-7237 – PHP remote file inclusion vulnerability in mod/nc_phpmyadmin/core/libraries/Them...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-7237</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-7237</guid>
    <pubDate>Tue, 31 Mar 2009 17:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-7237</strong></p>
  <p>PHP remote file inclusion vulnerability in mod/nc_phpmyadmin/core/libraries/Theme_Manager.class.php in Ixprim 2.0 allows remote attackers to execute arbitrary PHP code via a URL in an unspecified parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-7237">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-1151 – Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1151</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1151</guid>
    <pubDate>Thu, 26 Mar 2009 14:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-1151</strong></p>
  <p>Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1151">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-1149 – CRLF injection vulnerability in bs_disp_as_mime_type.php in the BLOB streaming f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1149</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1149</guid>
    <pubDate>Thu, 26 Mar 2009 14:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-1149</strong></p>
  <p>CRLF injection vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the (1) c_type and possibly (2) file_type parameters.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1149">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-0919 – XAMPP installs multiple packages with insecure default passwords, which makes it...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0919</guid>
    <pubDate>Mon, 16 Mar 2009 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-0919</strong></p>
  <p>XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "lampp" default password for the "nobody" account within the included ProFTPD installation, (2) a blank default password for the "root" account within the included MySQL installation, (3) a blank default password for the "pma" account within the phpMyAdmin inst…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-4096 – libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-4096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-4096</guid>
    <pubDate>Thu, 18 Sep 2008 15:04:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-4096</strong></p>
  <p>libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-4096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-2278 – Multiple PHP remote file inclusion vulnerabilities in DCP-Portal 6.1.1 allow rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-2278</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-2278</guid>
    <pubDate>Wed, 25 Apr 2007 20:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-2278</strong></p>
  <p>Multiple PHP remote file inclusion vulnerabilities in DCP-Portal 6.1.1 allow remote attackers to execute arbitrary PHP code via a URL in (1) the path parameter to library/adodb/adodb.inc.php, (2) the abs_path_editor parameter to library/editor/editor.php, or (3) the cfgfile_to_load parameter to admin/phpMyAdmin/libraries/common.lib.php.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-2278">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-1325 – The PMA_ArrayWalkRecursive function in libraries/common.lib.php in phpMyAdmin be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1325</guid>
    <pubDate>Wed, 07 Mar 2007 21:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-1325</strong></p>
  <p>The PMA_ArrayWalkRecursive function in libraries/common.lib.php in phpMyAdmin before 2.10.0.2 does not limit recursion on arrays provided by users, which allows context-dependent attackers to cause a denial of service (web server crash) via an array with many dimensions.  NOTE: it could be argued that this vulnerability is caused by a problem in PHP (CVE-2006-1549) and the proper fix should be in…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-6944 – phpMyAdmin before 2.9.1.1 allows remote attackers to bypass Allow/Deny access ru...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6944</guid>
    <pubDate>Fri, 19 Jan 2007 02:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-6944</strong></p>
  <p>phpMyAdmin before 2.9.1.1 allows remote attackers to bypass Allow/Deny access rules that use IP addresses via false headers.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2007-0203 – Multiple unspecified vulnerabilities in phpMyAdmin before 2.9.2-rc1 have unknown...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0203</guid>
    <pubDate>Thu, 11 Jan 2007 11:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2007-0203</strong></p>
  <p>Multiple unspecified vulnerabilities in phpMyAdmin before 2.9.2-rc1 have unknown impact and attack vectors.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0203">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-6374 – Multiple CRLF injection vulnerabilities in PhpMyAdmin 2.7.0-pl2 allow remote att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6374</guid>
    <pubDate>Thu, 07 Dec 2006 17:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-6374</strong></p>
  <p>Multiple CRLF injection vulnerabilities in PhpMyAdmin 2.7.0-pl2 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a phpMyAdmin cookie in (1) css/phpmyadmin.css.php, (2) db_create.php, (3) index.php, (4) left.php, (5) libraries/session.inc.php, (6) libraries/transformations/overview.php, (7) querywindow.php, (8) server_engines…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2006-6258 – The phpmyadmin subsystem in AlternC 0.9.5 and earlier transmits the SQL password...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6258</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6258</guid>
    <pubDate>Mon, 04 Dec 2006 11:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2006-6258</strong></p>
  <p>The phpmyadmin subsystem in AlternC 0.9.5 and earlier transmits the SQL password in cleartext in a cookie, which might allow remote attackers to obtain the password by sniffing or by conducting a cross-site scripting (XSS) attack.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6258">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-1804 – SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-1804</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-1804</guid>
    <pubDate>Tue, 18 Apr 2006 10:02:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-1804</strong></p>
  <p>SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to execute arbitrary SQL commands via the sql_query parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-1804">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-4450 – Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.7.0 allows remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-4450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-4450</guid>
    <pubDate>Wed, 21 Dec 2005 11:03:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-4450</strong></p>
  <p>Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.7.0 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag to server_privileges.php, as demonstrated using the dbname and checkprivs parameters.  NOTE: the provenance of this issue is unknown, although third parties imply that it is related to the disclosure of CVE-2005-4349, which was label…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-4450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-0567 – Multiple PHP remote file inclusion vulnerabilities in phpMyAdmin 2.6.1 allow rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-0567</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-0567</guid>
    <pubDate>Mon, 02 May 2005 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-0567</strong></p>
  <p>Multiple PHP remote file inclusion vulnerabilities in phpMyAdmin 2.6.1 allow remote attackers to execute arbitrary PHP code by modifying the (1) theme parameter to phpmyadmin.css.php or (2) cfg[Server][extension] parameter to database_interface.lib.php to reference a URL on a remote web server that contains the code.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-0567">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2004-1147 – phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-1147</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-1147</guid>
    <pubDate>Mon, 10 Jan 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2004-1147</strong></p>
  <p>phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-1147">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2004-2630 – The MIME transformation system (transformations/text_plain__external.inc.php) in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-2630</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-2630</guid>
    <pubDate>Fri, 31 Dec 2004 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2004-2630</strong></p>
  <p>The MIME transformation system (transformations/text_plain__external.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-2630">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2004-2631 – Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when L...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-2631</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-2631</guid>
    <pubDate>Fri, 31 Dec 2004 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2004-2631</strong></p>
  <p>Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary PHP code via a crafted table name.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-2631">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2004-2632 – phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration set...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-2632</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-2632</guid>
    <pubDate>Fri, 31 Dec 2004 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2004-2632</strong></p>
  <p>phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration settings and gain unauthorized access to MySQL servers via modified $cfg['Servers'] variables.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-2632">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2001-1060 – phpMyAdmin 2.2.0rc3 and earlier allows remote attackers to execute arbitrary com...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2001-1060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2001-1060</guid>
    <pubDate>Tue, 31 Jul 2001 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2001-1060</strong></p>
  <p>phpMyAdmin 2.2.0rc3 and earlier allows remote attackers to execute arbitrary commands by inserting them into (1) the strCopyTableOK argument in tbl_copy.php, or (2) the strRenameTableOK argument in tbl_rename.php.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2001-1060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2001-0478 – Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2001-0478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2001-0478</guid>
    <pubDate>Wed, 27 Jun 2001 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2001-0478</strong></p>
  <p>Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2001-0478">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
