
CVE-2015-8669
https://notcve.org/view.php?id=CVE-2015-8669
26 Dec 2015 — libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message. libraries/config/messages.inc.php en phpMyAdmin 4.0.x en versiones anteriores a 4.0.10.12, 4.4.x en versiones anteriores a 4.4.15.2 y 4.5.x en versiones anteriores a 4.5.3.1 permite a atacantes remotos obtener información sensible a través de una petición manipula... • http://lists.opensuse.org/opensuse-updates/2016-01/msg00014.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2015-7873 – Debian Security Advisory 3382-1
https://notcve.org/view.php?id=CVE-2015-7873
28 Oct 2015 — The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter. La funcionalidad de redireccionado en url.php en phpMyAdmin 4.4.x en versiones anteriores a 4.4.15.1 y 4.5.x en versiones anteriores a 4.5.1 permite a atacantes remotos suplantar contenido a través de un parámetro url. Several issues have been fixed in phpMyAdmin, the web administration tool for MySQL. • http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171311.html • CWE-254: 7PK - Security Features •

CVE-2015-6830 – Debian Security Advisory 3382-1
https://notcve.org/view.php?id=CVE-2015-6830
14 Sep 2015 — libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass a multiple-reCaptcha protection mechanism against brute-force credential guessing by providing a correct response to a single reCaptcha. Vulnerabilidad en libraries/plugins/auth/AuthenticationCookie.class.php en phpMyAdmin 4.3.x en versiones anteriores a 4.3.13.2 y 4.4.x en versiones anteriores a 4.4.14.1, permite a atacantes remotos eludir un mecanismo de pro... • http://lists.fedoraproject.org/pipermail/package-announce/2015-September/166294.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2015-3902 – Debian Security Advisory 3382-1
https://notcve.org/view.php?id=CVE-2015-3902
26 May 2015 — Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file. Múltiples vulnerabilidades de CSRF en el proceso de montaje en phpMyAdmin 4.0.x anterior a 4.0.10.10, 4.2.x anterior a 4.2.13.3, 4.3.x anterior a 4.3.13.1, y 4.4.x anterior a 4.4.6.1 permiten a atacantes ... • http://lists.opensuse.org/opensuse-updates/2015-07/msg00008.html • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2015-3903 – phpMyAdmin 4.4.6 Man-In-The-Middle
https://notcve.org/view.php?id=CVE-2015-3903
14 May 2015 — libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. libraries/Config.class.php en phpMyAdmin 4.0.x anterior a 4.0.10.10, 4.2.x anterior a 4.2.13.3, 4.3.x anterior a 4.3.13.1, y 4.4.x anterior a 4.4.6.1 deshabilita la verificación de los ce... • http://cxsecurity.com/issue/WLB-2015050095 • CWE-310: Cryptographic Issues •

CVE-2015-2206 – Debian Security Advisory 3382-1
https://notcve.org/view.php?id=CVE-2015-2206
09 Mar 2015 — libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests. libraries/select_lang.lib.php en phpMyAdmin 4.0.x anterior a 4.0.10.9, 4.2.x anterior a 4.2.13.2, y 4.3.x anterior a 4.3.11.1 incluye... • http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151331.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2011-3591
https://notcve.org/view.php?id=CVE-2011-3591
26 Dec 2014 — Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via a crafted row that triggers an improperly constructed confirmation message after inline-editing and save operations, related to (1) js/functions.js and (2) js/tbl_structure.js. Múltiples vulnerabilidades XSS en phpMyAdmin 3.4.x anterior a 3.4.5 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML através de una fila mod... • http://www.openwall.com/lists/oss-security/2011/09/30/8 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2011-3592
https://notcve.org/view.php?id=CVE-2011-3592
26 Dec 2014 — Multiple cross-site scripting (XSS) vulnerabilities in the PMA_unInlineEditRow function in js/sql.js in phpMyAdmin 3.4.x before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via a (1) database name, (2) table name, or (3) column name that is not properly handled after an inline-editing operation. Múltiples vulnerabilidades XSS en la función PMA_unInlineEditRow en js/sql.js en phpMyAdmin 3.4.x anterior a 3.4.5 permite a usuarios remotos autenticados inyectar secuencias de coma... • http://www.openwall.com/lists/oss-security/2011/09/30/8 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-9218 – phpMyAdmin 4.0.x/4.1.x/4.2.x - Denial of Service
https://notcve.org/view.php?id=CVE-2014-9218
08 Dec 2014 — libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a denial of service (resource consumption) via a long password. libraries/common.inc.php en phpMyAdmin 4.0.x anterior a 4.0.10.7, 4.1.x anterior a 4.1.14.8, y 4.2.x anterior a 4.2.13.1 permite a atacantes remotos causar una denegación de servicio (consumo de recursos) a través de una contraseña larga. Multiple vulnerabilities has been discovered and corrected in lib... • https://www.exploit-db.com/exploits/35539 • CWE-399: Resource Management Errors •

CVE-2014-9219 – Mandriva Linux Security Advisory 2014-243
https://notcve.org/view.php?id=CVE-2014-9219
08 Dec 2014 — Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter. Vulnerabilidad de XSS en la caracteristica de redirección en url.php en phpMyAdmin 4.2.x anterior a 4.2.13.1 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través del parámetro url. Multiple vulnerabilities has been discovered and corrected in libraries/common.inc.php in p... • http://www.mandriva.com/security/advisories?name=MDVSA-2014:243 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •