<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – phpMyAdmin</title>
  <link>https://cvedaily.com/pages/tags/phpmyadmin.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/phpmyadmin.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – phpMyAdmin</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:51 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-41930 – Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41930</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41930</guid>
    <pubDate>Wed, 06 May 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41930</strong></p>
  <p>Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configuration that allows unauthenticated attackers to access the bundled phpMyAdmin container with pre-configured database credentials. Attackers can connect to the phpMyAdmin port to gain unrestricted read and write access to the entire Vvveb database, including administrator password…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41930">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37116 – GUnet OpenEclass 1.7.3 includes phpMyAdmin 2.10.0.2 by default, which allows rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37116</guid>
    <pubDate>Tue, 03 Feb 2026 18:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37116</strong></p>
  <p>GUnet OpenEclass 1.7.3 includes phpMyAdmin 2.10.0.2 by default, which allows remote logins. Attackers with access to the platform can remotely access phpMyAdmin and, after uploading a shell, view the config.php file to obtain the MySQL password, leading to full database compromise.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-51539 – EzGED3 3.5.0 contains an unauthenticated arbitrary file read vulnerability due t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-51539</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-51539</guid>
    <pubDate>Tue, 19 Aug 2025 16:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-51539</strong></p>
  <p>EzGED3 3.5.0 contains an unauthenticated arbitrary file read vulnerability due to improper access control and insufficient input validation in a script exposed via the web interface. A remote attacker can supply a crafted path parameter to a PHP script to read arbitrary files from the filesystem. The script lacks both authentication checks and secure path handling, allowing directory traversal at…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-51539">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-46188 – SourceCodester Client Database Management System 1.0 is vulnerable to SQL Inject...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46188</guid>
    <pubDate>Fri, 09 May 2025 16:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-46188</strong></p>
  <p>SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-24530 – An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24530</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24530</guid>
    <pubDate>Thu, 23 Jan 2025 06:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-24530</strong></p>
  <p>An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the check tables feature. A crafted table or database name could be used for XSS.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24530">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-24529 – An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24529</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24529</guid>
    <pubDate>Thu, 23 Jan 2025 06:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-24529</strong></p>
  <p>An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the Insert tab.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24529">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-25727 – In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trig...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25727</guid>
    <pubDate>Mon, 13 Feb 2023 06:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-25727</strong></p>
  <p>In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-22452 – SQL Injection vulnerability in function getTableCreationQuery in CreateAddField...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-22452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-22452</guid>
    <pubDate>Thu, 26 Jan 2023 21:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-22452</strong></p>
  <p>SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-2407 – The WP phpMyAdmin WordPress plugin before 5.2.0.4 does not escape some of its se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2407</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2407</guid>
    <pubDate>Mon, 22 Aug 2022 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-2407</strong></p>
  <p>The WP phpMyAdmin WordPress plugin before 5.2.0.4 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2407">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-0813 – PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0813</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0813</guid>
    <pubDate>Thu, 10 Mar 2022 17:44:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-0813</strong></p>
  <p>PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0813">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-23808 – An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23808</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23808</guid>
    <pubDate>Sat, 22 Jan 2022 02:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-23808</strong></p>
  <p>An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23808">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-23807 – An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23807</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23807</guid>
    <pubDate>Sat, 22 Jan 2022 02:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-23807</strong></p>
  <p>An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23807">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-26939 – An information disclosure issue exists in henriquedornas 5.2.17 because an attac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26939</guid>
    <pubDate>Wed, 10 Feb 2021 18:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-26939</strong></p>
  <p>An information disclosure issue exists in henriquedornas 5.2.17 because an attacker can dump phpMyAdmin SQL content. NOTE: third parties report that this is a site-specific problem</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-22278 – phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vend...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-22278</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-22278</guid>
    <pubDate>Wed, 04 Nov 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-22278</strong></p>
  <p>phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1236</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22278">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-26935 – An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26935</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26935</guid>
    <pubDate>Sat, 10 Oct 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-26935</strong></p>
  <p>An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26935">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-26934 – phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26934</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26934</guid>
    <pubDate>Sat, 10 Oct 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-26934</strong></p>
  <p>phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26934">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-11441 – phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11441</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11441</guid>
    <pubDate>Tue, 31 Mar 2020 17:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-11441</strong></p>
  <p>phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11441">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-10803 – In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10803</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10803</guid>
    <pubDate>Sun, 22 Mar 2020 05:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-10803</strong></p>
  <p>In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which when retrieved (for instance, through the Browse…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10803">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10802 – In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10802</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10802</guid>
    <pubDate>Sun, 22 Mar 2020 05:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10802</strong></p>
  <p>In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/classes/Controllers/Table/TableSearchController.php. An attacker can generate a crafted database or table name. The attack can be performed if a user attempts certain search operatio…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10802">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10804 – In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10804</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10804</guid>
    <pubDate>Sun, 22 Mar 2020 04:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10804</strong></p>
  <p>In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A malicious user with access to the server could create a crafted username, and then trick the victim into performing specific actions with that user account (such as editing its privi…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10804">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-4454 – WordPress Portable phpMyAdmin Plugin 1.4.1 has Multiple Security Bypass Vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4454</guid>
    <pubDate>Tue, 18 Feb 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-4454</strong></p>
  <p>WordPress Portable phpMyAdmin Plugin 1.4.1 has Multiple Security Bypass Vulnerabilities</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-4462 – WordPress Portable phpMyAdmin Plugin has an authentication bypass vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4462</guid>
    <pubDate>Mon, 27 Jan 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-4462</strong></p>
  <p>WordPress Portable phpMyAdmin Plugin has an authentication bypass vulnerability</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-5504 – In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5504</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5504</guid>
    <pubDate>Thu, 09 Jan 2020 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-5504</strong></p>
  <p>In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5504">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-15235 – CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.864 allows an attacker to g...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15235</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15235</guid>
    <pubDate>Tue, 17 Dec 2019 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-15235</strong></p>
  <p>CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.864 allows an attacker to get a victim's session file name from /home/[USERNAME]/tmp/session/sess_xxxxxx, and the victim's token value from /usr/local/cwpsrv/logs/access_log, then use them to gain access to the victim's password (for the OS and phpMyAdmin) via an attacker account. This is different from CVE-2019-14782.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15235">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-14782 – CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.856 through 0.9.8.864 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14782</guid>
    <pubDate>Tue, 17 Dec 2019 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-14782</strong></p>
  <p>CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.856 through 0.9.8.864 allows an attacker to get a victim's session file name from the /tmp directory, and the victim's token value from /usr/local/cwpsrv/logs/access_log, then use them to make a request to extract the victim's password (for the OS and phpMyAdmin) via an attacker account.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-19617 – phpMyAdmin before 4.9.2 does not escape certain Git information, related to libr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19617</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19617</guid>
    <pubDate>Fri, 06 Dec 2019 03:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-19617</strong></p>
  <p>phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19617">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-18622 – An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table nam...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18622</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18622</guid>
    <pubDate>Fri, 22 Nov 2019 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-18622</strong></p>
  <p>An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18622">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-12922 – A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12922</guid>
    <pubDate>Fri, 13 Sep 2019 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-12922</strong></p>
  <p>A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-14721 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14721</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14721</guid>
    <pubDate>Tue, 10 Sep 2019 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-14721</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to remove a target user from phpMyAdmin via an attacker account.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14721">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-14246 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14246</guid>
    <pubDate>Wed, 21 Aug 2019 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-14246</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to discover phpMyAdmin passwords (of any user in /etc/passwd) via an attacker account.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-20886 – cPanel before 74.0.0 insecurely stores phpMyAdmin session files (SEC-418).</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-20886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-20886</guid>
    <pubDate>Thu, 01 Aug 2019 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-20886</strong></p>
  <p>cPanel before 74.0.0 insecurely stores phpMyAdmin session files (SEC-418).</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-922</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-20886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-12616 – An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12616</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12616</guid>
    <pubDate>Wed, 05 Jun 2019 05:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-12616</strong></p>
  <p>An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken <img> tag pointing at the victim's phpMyAdmin database, and the attacker can potentially deliver a payload (such as a specific INSERT or DELETE statement) to the victim.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12616">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-11768 – An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was report...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11768</guid>
    <pubDate>Wed, 05 Jun 2019 05:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-11768</strong></p>
  <p>An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an SQL injection attack through the designer feature.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-6799 – An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-6799</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-6799</guid>
    <pubDate>Sat, 26 Jan 2019 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-6799</strong></p>
  <p>An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. This is related to the mysql.allow_local_infile PHP configuration, and the inadvertent ignoring of "options(MYSQLI_OPT_LOCAL_INFILE" calls.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-6799">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-6798 – An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-6798</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-6798</guid>
    <pubDate>Sat, 26 Jan 2019 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-6798</strong></p>
  <p>An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can be used to trigger a SQL injection attack through the designer feature.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-6798">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-19970 – In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19970</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19970</guid>
    <pubDate>Tue, 11 Dec 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-19970</strong></p>
  <p>In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19970">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-19969 – phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19969</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19969</guid>
    <pubDate>Tue, 11 Dec 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-19969</strong></p>
  <p>phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is possible to perform harmful SQL operations such as renaming databases, creating new tables/routines, deleting designer pages, adding/deleting users, updating user passwords, killing SQL processes, etc.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19969">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-19968 – An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19968</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19968</guid>
    <pubDate>Tue, 11 Dec 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-19968</strong></p>
  <p>An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19968">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-15605 – An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-15605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-15605</guid>
    <pubDate>Fri, 24 Aug 2018 19:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-15605</strong></p>
  <p>An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted file to manipulate an authenticated user who loads that file through the import feature.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-15605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-12613 – An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-12613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-12613</guid>
    <pubDate>Thu, 21 Jun 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-12613</strong></p>
  <p>An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages. An attacker must be authenticated, except in the "$cfg['AllowArbitraryServer'] = true" case (where an attack…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-12613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-12581 – An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-12581</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-12581</guid>
    <pubDate>Thu, 21 Jun 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-12581</strong></p>
  <p>An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted database name to trigger an XSS attack when that database is referenced from the Designer feature.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-12581">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-18264 – An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18264</guid>
    <pubDate>Tue, 01 May 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-18264</strong></p>
  <p>An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0.10.20, 4.4.x, 4.6.x, and 4.7.0 prereleases. The restrictions caused by $cfg['Servers'][$i]['AllowNoPassword'] = false are bypassed under certain PHP versions (e.g., version 5). This can allow the login of users who have no password set even if the administrator has set $cfg['Servers'][$i]['AllowNoPassword'] to false…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-10188 – phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10188</guid>
    <pubDate>Thu, 19 Apr 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-10188</strong></p>
  <p>phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations.js, libraries/classes/Operations.php, and sql.php.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-7260 – Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-7260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-7260</guid>
    <pubDate>Wed, 21 Feb 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-7260</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-7260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1000499 – phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weak...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000499</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000499</guid>
    <pubDate>Wed, 03 Jan 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1000499</strong></p>
  <p>phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000499">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1000018 – phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000018</guid>
    <pubDate>Mon, 17 Jul 2017 13:18:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1000018</strong></p>
  <p>phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication status by using a specially crafted table name</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1000017 – phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000017</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000017</guid>
    <pubDate>Mon, 17 Jul 2017 13:18:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1000017</strong></p>
  <p>phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to an arbitrary MySQL server</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000017">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-1000015 – phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a CSS injection attack through cr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000015</guid>
    <pubDate>Mon, 17 Jul 2017 13:18:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-1000015</strong></p>
  <p>phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a CSS injection attack through crafted cookie parameters</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1000014 – phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a DOS weakness in the table editi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000014</guid>
    <pubDate>Mon, 17 Jul 2017 13:18:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1000014</strong></p>
  <p>phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a DOS weakness in the table editing functionality</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-1000013 – phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to an open redirect weakness</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000013</guid>
    <pubDate>Mon, 17 Jul 2017 13:18:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-1000013</strong></p>
  <p>phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to an open redirect weakness</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6621 – The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6621</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6621</guid>
    <pubDate>Tue, 31 Jan 2017 19:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6621</strong></p>
  <p>The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6621">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-9866 – An issue was discovered in phpMyAdmin. When the arg_separator is different from ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9866</guid>
    <pubDate>Sun, 11 Dec 2016 03:00:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-9866</strong></p>
  <p>An issue was discovered in phpMyAdmin. When the arg_separator is different from its default & value, the CSRF token was not properly stripped from the return URL of the preference import action. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-9865 – An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9865</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9865</guid>
    <pubDate>Sun, 11 Dec 2016 03:00:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-9865</strong></p>
  <p>An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9865">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9864 – An issue was discovered in phpMyAdmin. With a crafted username or a table name, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9864</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9864</guid>
    <pubDate>Sun, 11 Dec 2016 03:00:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9864</strong></p>
  <p>An issue was discovered in phpMyAdmin. With a crafted username or a table name, it was possible to inject SQL statements in the tracking functionality that would run with the privileges of the control user. This gives read and write access to the tables of the configuration storage database, and if the control user has the necessary privileges, read access to some tables of the MySQL database. Al…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9864">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9863 – An issue was discovered in phpMyAdmin. With a very large request to table partit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9863</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9863</guid>
    <pubDate>Sun, 11 Dec 2016 03:00:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9863</strong></p>
  <p>An issue was discovered in phpMyAdmin. With a very large request to table partitioning function, it is possible to invoke a Denial of Service (DoS) attack. All 4.6.x versions (prior to 4.6.5) are affected.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9863">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9862 – An issue was discovered in phpMyAdmin. With a crafted login request it is possib...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9862</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9862</guid>
    <pubDate>Sun, 11 Dec 2016 03:00:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9862</strong></p>
  <p>An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9862">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9861 – An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9861</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9861</guid>
    <pubDate>Sun, 11 Dec 2016 03:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9861</strong></p>
  <p>An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it was possible to bypass the URL white-list protection. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9861">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-9860 – An issue was discovered in phpMyAdmin. An unauthenticated user can execute a den...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9860</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9860</guid>
    <pubDate>Sun, 11 Dec 2016 03:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-9860</strong></p>
  <p>An issue was discovered in phpMyAdmin. An unauthenticated user can execute a denial of service attack when phpMyAdmin is running with $cfg['AllowArbitraryServer']=true. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9860">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-9859 – An issue was discovered in phpMyAdmin. With a crafted request parameter value it...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9859</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9859</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-9859</strong></p>
  <p>An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in import feature. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9859">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-9858 – An issue was discovered in phpMyAdmin. With a crafted request parameter value it...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9858</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9858</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-9858</strong></p>
  <p>An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in saved searches feature. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9858">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-9857 – An issue was discovered in phpMyAdmin. XSS is possible because of a weakness in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9857</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9857</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-9857</strong></p>
  <p>An issue was discovered in phpMyAdmin. XSS is possible because of a weakness in a regular expression used in some JavaScript processing. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9857">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-9856 – An XSS issue was discovered in phpMyAdmin because of an improper fix for CVE-201...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9856</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9856</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-9856</strong></p>
  <p>An XSS issue was discovered in phpMyAdmin because of an improper fix for CVE-2016-2559 in PMASA-2016-10. This issue is resolved by using a copy of a hash to avoid a race condition. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9856">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-9855 – An issue was discovered in phpMyAdmin. By calling some scripts that are part of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9855</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9855</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-9855</strong></p>
  <p>An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to th…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9855">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-9854 – An issue was discovered in phpMyAdmin. By calling some scripts that are part of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9854</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9854</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-9854</strong></p>
  <p>An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to th…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9854">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-9853 – An issue was discovered in phpMyAdmin. By calling some scripts that are part of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9853</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9853</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-9853</strong></p>
  <p>An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to th…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9853">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-9852 – An issue was discovered in phpMyAdmin. By calling some scripts that are part of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9852</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9852</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-9852</strong></p>
  <p>An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to th…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9852">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-9851 – An issue was discovered in phpMyAdmin. With a crafted request parameter value it...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9851</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9851</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-9851</strong></p>
  <p>An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to bypass the logout timeout. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9851">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-9850 – An issue was discovered in phpMyAdmin. Username matching for the allow/deny rule...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9850</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9850</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-9850</strong></p>
  <p>An issue was discovered in phpMyAdmin. Username matching for the allow/deny rules may result in wrong matches and detection of the username in the rule due to non-constant execution time. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9850">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-9849 – An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9849</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-9849</strong></p>
  <p>An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restriction ($cfg['Servers'][$i]['AllowRoot']) and deny rules for username by using Null Byte in the username. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-9848 – An issue was discovered in phpMyAdmin. phpinfo (phpinfo.php) shows PHP informati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9848</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9848</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-9848</strong></p>
  <p>An issue was discovered in phpMyAdmin. phpinfo (phpinfo.php) shows PHP information including values of HttpOnly cookies. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9848">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-9847 – An issue was discovered in phpMyAdmin. When the user does not specify a blowfish...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9847</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9847</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-9847</strong></p>
  <p>An issue was discovered in phpMyAdmin. When the user does not specify a blowfish_secret key for encrypting cookies, phpMyAdmin generates one at runtime. A vulnerability was reported where the way this value is created uses a weak algorithm. This could allow an attacker to determine the user's blowfish_secret and potentially decrypt their cookies. All 4.6.x versions (prior to 4.6.5), 4.4.x version…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9847">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6633 – An issue was discovered in phpMyAdmin. phpMyAdmin can be used to trigger a remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6633</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6633</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6633</strong></p>
  <p>An issue was discovered in phpMyAdmin. phpMyAdmin can be used to trigger a remote code execution attack against certain PHP installations that are running with the dbase extension. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6633">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6632 – An issue was discovered in phpMyAdmin where, under certain conditions, phpMyAdmi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6632</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6632</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6632</strong></p>
  <p>An issue was discovered in phpMyAdmin where, under certain conditions, phpMyAdmin may not delete temporary files during the import of ESRI files. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6632">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6631 – An issue was discovered in phpMyAdmin. A user can execute a remote code executio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6631</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6631</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6631</strong></p>
  <p>An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmin is being run as a CGI application. Under certain server configurations, a user can pass a query string which is executed as a command-line argument by the file generator_plugin.sh. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (pri…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6631">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6630 – An issue was discovered in phpMyAdmin. An authenticated user can trigger a denia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6630</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6630</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6630</strong></p>
  <p>An issue was discovered in phpMyAdmin. An authenticated user can trigger a denial-of-service (DoS) attack by entering a very long password at the change password dialog. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6630">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-6629 – An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6629</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-6629</strong></p>
  <p>An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive. An attacker could reuse certain cookie values in a way of bypassing the servers defined by ArbitraryServerRegexp. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6628 – An issue was discovered in phpMyAdmin. An attacker may be able to trigger a user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6628</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6628</strong></p>
  <p>An issue was discovered in phpMyAdmin. An attacker may be able to trigger a user to download a specially crafted malicious SVG file. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6627 – An issue was discovered in phpMyAdmin. An attacker can determine the phpMyAdmin ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6627</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6627</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6627</strong></p>
  <p>An issue was discovered in phpMyAdmin. An attacker can determine the phpMyAdmin host location through the file url.php. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6627">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6626 – An issue was discovered in phpMyAdmin. An attacker could redirect a user to a ma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6626</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6626</strong></p>
  <p>An issue was discovered in phpMyAdmin. An attacker could redirect a user to a malicious web page. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6625 – An issue was discovered in phpMyAdmin. An attacker can determine whether a user ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6625</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6625</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6625</strong></p>
  <p>An issue was discovered in phpMyAdmin. An attacker can determine whether a user is logged in to phpMyAdmin. The user's session, username, and password are not compromised by this vulnerability. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6625">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6624 – An issue was discovered in phpMyAdmin involving improper enforcement of the IP-b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6624</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6624</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6624</strong></p>
  <p>An issue was discovered in phpMyAdmin involving improper enforcement of the IP-based authentication rules. When phpMyAdmin is used with IPv6 in a proxy server environment, and the proxy server is in the allowed range but the attacking computer is not allowed, this vulnerability can allow the attacking computer to connect despite the IP rules. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (p…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6624">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6623 – An issue was discovered in phpMyAdmin. An authorized user can cause a denial-of-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6623</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6623</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6623</strong></p>
  <p>An issue was discovered in phpMyAdmin. An authorized user can cause a denial-of-service (DoS) attack on a server by passing large values to a loop. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6623">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6622 – An issue was discovered in phpMyAdmin. An unauthenticated user is able to execut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6622</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6622</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6622</strong></p>
  <p>An issue was discovered in phpMyAdmin. An unauthenticated user is able to execute a denial-of-service (DoS) attack by forcing persistent connections when phpMyAdmin is running with $cfg['AllowArbitraryServer']=true. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6622">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-6620 – An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserializ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6620</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6620</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-6620</strong></p>
  <p>An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. The unserialization can result in code execution because of the interaction with object instantiation and autoloading. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6620">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6619 – An issue was discovered in phpMyAdmin. In the user interface preference feature,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6619</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6619</strong></p>
  <p>An issue was discovered in phpMyAdmin. In the user interface preference feature, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6618 – An issue was discovered in phpMyAdmin. The transformation feature allows a user ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6618</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6618</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6618</strong></p>
  <p>An issue was discovered in phpMyAdmin. The transformation feature allows a user to trigger a denial-of-service (DoS) attack against the server. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6618">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6617 – An issue was discovered in phpMyAdmin. A specially crafted database and/or table...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6617</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6617</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6617</strong></p>
  <p>An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4) are affected.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6617">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6616 – An issue was discovered in phpMyAdmin. In the "User group" and "Designer" featur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6616</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6616</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6616</strong></p>
  <p>An issue was discovered in phpMyAdmin. In the "User group" and "Designer" features, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4) and 4.4.x versions (prior to 4.4.15.8) are affected.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6616">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6615 – XSS issues were discovered in phpMyAdmin. This affects navigation pane and datab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6615</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6615</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6615</strong></p>
  <p>XSS issues were discovered in phpMyAdmin. This affects navigation pane and database/table hiding feature (a specially-crafted database name can be used to trigger an XSS attack); the "Tracking" feature (a specially-crafted query can be used to trigger an XSS attack); and GIS visualization feature. All 4.6.x versions (prior to 4.6.4) and 4.4.x versions (prior to 4.4.15.8) are affected.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6615">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6614 – An issue was discovered in phpMyAdmin involving the %u username replacement func...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6614</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6614</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6614</strong></p>
  <p>An issue was discovered in phpMyAdmin involving the %u username replacement functionality of the SaveDir and UploadDir features. When the username substitution is configured, a specially-crafted user name can be used to circumvent restrictions to traverse the file system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6614">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6613 – An issue was discovered in phpMyAdmin. A user can specially craft a symlink on d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6613</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6613</strong></p>
  <p>An issue was discovered in phpMyAdmin. A user can specially craft a symlink on disk, to a file which phpMyAdmin is permitted to read but the user is not, which phpMyAdmin will then expose to the user. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6612 – An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOCAL INFILE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6612</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6612</strong></p>
  <p>An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOCAL INFILE functionality to expose files on the server to the database system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6611 – An issue was discovered in phpMyAdmin. A specially crafted database and/or table...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6611</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6611</strong></p>
  <p>An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6610 – A full path disclosure vulnerability was discovered in phpMyAdmin where a user c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6610</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6610</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6610</strong></p>
  <p>A full path disclosure vulnerability was discovered in phpMyAdmin where a user can trigger a particular error in the export mechanism to discover the full path of phpMyAdmin on the disk. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6610">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6609 – An issue was discovered in phpMyAdmin. A specially crafted database name could b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6609</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6609</strong></p>
  <p>An issue was discovered in phpMyAdmin. A specially crafted database name could be used to run arbitrary PHP commands through the array export feature. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6608 – XSS issues were discovered in phpMyAdmin. This affects the database privilege ch...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6608</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6608</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6608</strong></p>
  <p>XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted database names can trigger the XSS attack. All 4.6.x versions (prior to 4.6.4) are affected.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6608">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6607 – XSS issues were discovered in phpMyAdmin. This affects Zoom search (specially cr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6607</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6607</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6607</strong></p>
  <p>XSS issues were discovered in phpMyAdmin. This affects Zoom search (specially crafted column content can be used to trigger an XSS attack); GIS editor (certain fields in the graphical GIS editor are not properly escaped and can be used to trigger an XSS attack); Relation view; the following Transformations: Formatted, Imagelink, JPEG: Upload, RegexValidation, JPEG inline, PNG inline, and transfor…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6607">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6606 – An issue was discovered in cookie encryption in phpMyAdmin. The decryption of th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6606</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6606</strong></p>
  <p>An issue was discovered in cookie encryption in phpMyAdmin. The decryption of the username/password is vulnerable to a padding oracle attack. This can allow an attacker who has access to a user's browser cookie file to decrypt the username and password. Furthermore, the same initialization vector (IV) is used to hash the username and password stored in the phpMyAdmin cookie. If a user has the sam…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-4412 – An issue was discovered in phpMyAdmin. A user can be tricked into following a li...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-4412</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-4412</guid>
    <pubDate>Sun, 11 Dec 2016 02:59:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-4412</strong></p>
  <p>An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token. All 4.0.x versions (prior to 4.0.10.16) are affected.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-4412">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-5099 – Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5099</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5099</guid>
    <pubDate>Tue, 05 Jul 2016 01:59:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-5099</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5099">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
