CVE-2007-5976
https://notcve.org/view.php?id=CVE-2007-5976
SQL injection vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to execute arbitrary SQL commands via the db parameter. Vulnerabilidad de inyección SQL en el db_create.php en el phpMyAdmin anterior al 2.11.2.1 permite a usuarios remotos autenticados con privilegios de CREATE DATABASE ejecutar comandos SQL de su elección a través del parámetro db. • http://secunia.com/advisories/27630 http://secunia.com/advisories/27753 http://sourceforge.net/project/shownotes.php?release_id=553333 http://www.digitrustgroup.com/advisories/tdg-advisory071108a.html http://www.mandriva.com/security/advisories?name=MDKSA-2007:229 http://www.securityfocus.com/bid/26512 http://www.vupen.com/english/advisories/2007/3824 https://exchange.xforce.ibmcloud.com/vulnerabilities/38403 https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00777.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2007-5977
https://notcve.org/view.php?id=CVE-2007-5977
Cross-site scripting (XSS) vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to inject arbitrary web script or HTML via a hex-encoded IMG element in the db parameter in a POST request, a different vulnerability than CVE-2006-6942. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el db_create.php del phpMyAdmin anterior al 2.11.2.1 permite a usuarios remotos autenticados con privilegios de CREATE DATABASE la inyección de secuencias de comandos web o HTML de su elección a través de un elemento IMG con codificación hex en el parámetro db de una petición POST. Vulnerabilidad diferente a la CVE-2006-6942. • http://secunia.com/advisories/27630 http://secunia.com/advisories/27753 http://sourceforge.net/project/shownotes.php?release_id=553333 http://www.digitrustgroup.com/advisories/tdg-advisory071108a.html http://www.mandriva.com/security/advisories?name=MDKSA-2007:229 http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-7 http://www.securityfocus.com/bid/26512 http://www.vupen.com/english/advisories/2007/3824 https://exchange.xforce.ibmcloud.com/vulnerabilities/38404 https://www. • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2007-5589 – phpMyAdmin 2.11.1 - 'Server_Status.php' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2007-5589
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.11.1.2 allow remote attackers to inject arbitrary web script or HTML via certain input available in (1) PHP_SELF in (a) server_status.php, and (b) grab_globals.lib.php, (c) display_change_password.lib.php, and (d) common.lib.php in libraries/; and certain input available in PHP_SELF and (2) PATH_INFO in libraries/common.inc.php. NOTE: there might also be other vectors related to (3) REQUEST_URI. Múltiples vulnerabilidades de tipo cross-site scripting (XSS) en phpMyAdmin versiones anteriores a 2.11.1.2, permiten a atacantes remotos inyectar script web o HTML arbitrario por medio de cierta entrada disponible en (1) PHP_SELF en (a) el archivo server_status.php, y las bibliotecas (b) grab_globals.lib.php, (c) display_change_password.lib.php y (d) common.lib.php en libraries/; y ciertas entradas disponibles en PHP_SELF y (2) PATH_INFO en la biblioteca libraries/common.inc.php. NOTA: también puede haber otros vectores relacionados con (3) REQUEST_URI. • https://www.exploit-db.com/exploits/30733 http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html http://osvdb.org/37939 http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/branches/MAINT_2_11_1/phpMyAdmin/ChangeLog?r1=10796&r2=10795&pathrev=10796 http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin?view=rev&revision=10796 http://secunia.com/advisories/27246 http://secunia.com/advisories/27506 http://secunia.com/advisories/27595 http://secunia.com/advisories/29323 h • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2007-1325
https://notcve.org/view.php?id=CVE-2007-1325
The PMA_ArrayWalkRecursive function in libraries/common.lib.php in phpMyAdmin before 2.10.0.2 does not limit recursion on arrays provided by users, which allows context-dependent attackers to cause a denial of service (web server crash) via an array with many dimensions. NOTE: it could be argued that this vulnerability is caused by a problem in PHP (CVE-2006-1549) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in phpMyAdmin. La función PMA_ArrayWalkRecursive en el libraries/common.lib.php del phpMyAdmin anterior al 2.10.0.2 no tiene límite en la recursividad de los arrays proporcionados por los usuarios, lo que permite a atacantes dependientes del contexto provocar una denegación de servicio (caída del servidor web) mediante un array con múltiples dimensiones. NOTA: puede ser discutido que esta vulnerabilidad está provocada por un problema en el PHP (CVE-2006-1549) y la solución adecuada debe de ser en PHP; con lo cual esto no debería ser tratado como una vulnerabilidad en el phpMyAdmin. • http://osvdb.org/36834 http://secunia.com/advisories/26733 http://sourceforge.net/tracker/index.php?func=detail&aid=1671813&group_id=23067&atid=377408 http://www.mandriva.com/security/advisories?name=MDKSA-2007:199 http://www.php-security.org/MOPB/MOPB-02-2007.html http://www.php.net/ChangeLog-4.php http://www.php.net/releases/4_4_8.php http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-3 http://www.securityfocus.com/bid/22841 http://www.us. •
CVE-2006-6942 – phpMyAdmin 2.x - 'db_create.php?db' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2006-6942
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1) a comment for a table name, as exploited through (a) db_operations.php, (2) the db parameter to (b) db_create.php, (3) the newname parameter to db_operations.php, the (4) query_history_latest, (5) query_history_latest_db, and (6) querydisplay_tab parameters to (c) querywindow.php, and (7) the pos parameter to (d) sql.php. Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en PhpMyAdmin versiones anteriores a 2.9.1.1 permite a atacantes remotos inyectar scripts web o HTML de su elección mediante (1) un comentario en un nombre de talba, tal y como se explota a través de (a) db_operations.php, (2) el parámetro db en (b) db_create.php, (3) el parámetro newname en db_operations.php, el parámetro(4) query_history_latest, (5) query_history_latest_db, y (6) querydisplay_tab en (c) querywindow.php, y (7) el parámetro pos en(d) sql.php. • https://www.exploit-db.com/exploits/29058 https://www.exploit-db.com/exploits/29059 https://www.exploit-db.com/exploits/29060 https://www.exploit-db.com/exploits/29061 http://marc.info/?l=bugtraq&m=116370414309444&w=2 http://secunia.com/advisories/26733 http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2006-7 http://www.securityfocus.com/bid/21137 http://www.us.debian.org/security/2007/dsa-1370 http://www.vupen.com/english/advisories/2006/4572 https • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •