This CPE summary could be partial or incomplete. Please contact us for a detailed listing.
Summary
| Summuary | |
|---|---|
| CPE Name | cpe:/a:phpmyadmin:phpmyadmin:2.0.4 |
| Detail | |||
|---|---|---|---|
| Vendor | Phpmyadmin | First view | 2001-07-31 |
| Product | Phpmyadmin | Last view | 2009-07-01 |
| Version | 2.0.4 | Type | Application |
| Edition | |||
| Language | |||
| Update | |||
| CPE Product | cpe:/a:phpmyadmin:phpmyadmin | ||
Activity : Yearly
Related : CVE
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 4.3 | 2009-07-01 | CVE-2009-2284 | Network | Medium | None Requ... | |
| 4.3 | 2008-09-30 | CVE-2008-4326 | Network | Medium | None Requ... | |
| 8.5 | 2008-09-18 | CVE-2008-4096 | Network | Medium | Requires ... | |
| 2.6 | 2008-08-04 | CVE-2008-3457 | Network | High | None Requ... | |
| 6.4 | 2008-08-04 | CVE-2008-3456 | Network | Low | None Requ... | |
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 3.5 | 2008-07-16 | CVE-2008-3197 | Network | Medium | Requires ... | |
| 2.6 | 2007-11-23 | CVE-2007-6100 | Network | High | None Requ... | |
| 5.8 | 2006-07-06 | CVE-2006-3388 | Network | Medium | None Requ... | |
| 4.3 | 2006-04-10 | CVE-2006-1678 | Network | Medium | None Requ... | |
| 4.3 | 2005-12-08 | CVE-2005-3665 | Network | Medium | None Requ... | |
| 4.3 | 2005-09-08 | CVE-2005-2869 | Network | Medium | None Requ... | |
| 4.3 | 2005-05-02 | CVE-2005-0992 | Network | Medium | None Requ... | |
| 5 | 2005-05-02 | CVE-2005-0459 | Network | Low | None Requ... | |
| 5 | 2004-03-03 | CVE-2004-0129 | Network | Low | None Requ... | |
| 7.5 | 2001-07-31 | CVE-2001-1060 | Network | Low | None Requ... |
CWE : Common Weakness Enumeration
| % | id | Name |
|---|---|---|
| 57% (4) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
| 14% (1) | CWE-352 | Cross-Site Request Forgery (CSRF) |
| 14% (1) | CWE-59 | Improper Link Resolution Before File Access ('Link Following') |
| 14% (1) | CWE-20 | Improper Input Validation |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 55514 | phpMyAdmin Crafted SQL Bookmark XSS |
| 48480 | phpMyAdmin libraries/js_escape.lib.php PMA_escapeJsString() Function MSIE Nul... |
| 48154 | phpMyAdmin server_databases.php sort_by Variable Arbitrary PHP Code Execution |
| 47487 | phpMyAdmin setup.php Configuration Manipulation Based XSS |
| 47486 | phpMyAdmin setup.php Cross-Frame Scripting |
| id | Description |
|---|---|
| 47322 | phpMyAdmin index.php Multiple Parameter CSRF |
| 47321 | phpMyAdmin db_create.php db Parameter CSRF |
| 38835 | phpMyAdmin index.php convcharset Parameter XSS |
| 26949 | phpMyAdmin table Parameter XSS |
| 24450 | phpMyAdmin Themes Directory Unspecified Scripts XSS |
| 21487 | phpMyAdmin /libraries Directory Multiple Unspecified Script XSS |
| 21486 | phpMyAdmin HTTP_HOST Parameter XSS |
| 19049 | phpMyAdmin Cookie Username Field XSS |
| 19048 | phpMyAdmin error.php error Parameter XSS |
| 15226 | phpMyAdmin index.php convcharset Parameter XSS |
| 8505 | phpMyAdmin /libraries/select_lang.lib.php Direct Request Path Disclosure |
| 8401 | phpMyAdmin tbl_rename.php Arbitrary Command Execution |
| 8400 | phpMyAdmin tbl_copy.php Arbitrary Command Execution |
| 3800 | phpMyAdmin export.php what Parameter Traversal Arbitrary File Access |








