phpMyAdmin是phpMyAdmin团队开发的一套免费的、基于Web的MySQL数据库管理工具。该工具能够创建和删除数据库,创建、删除、修改数据库表,执行SQL脚本命令等。 phpMyAdmin 3.3.10.2之前的3.x版本和3.4.3.1之前的3.4.x版本的Swekey认证功能中的libraries/auth/swekey/swekey.auth.lib.php为已在查询字符串中引用的任意参数分配值。远程攻击者可借助特制请求修改SESSION超全局数组。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2010-4554 | SquirrelMail functions/page_header.php信息泄露漏洞 | |
| CVE-2010-4555 | SquirrelMail多个跨站脚本攻击漏洞 | |
| CVE-2011-0287 | Research In Motion BlackBerry Enterprise Server Administration API信息泄露漏洞 | |
| CVE-2011-2023 | SquirrelMail functions/mime.php STYLE元素跨站脚本攻击漏洞 | |
| CVE-2011-2220 | Novell File Reporter Engine RECORD元素解析栈缓冲区溢出漏洞 | |
| CVE-2011-2506 | phpMyAdmin setup/lib/ConfigGenerator.class.php代码注入漏洞 | |
| CVE-2011-2507 | phpMyAdmin 'PMA_createTargetTables()'函数任意PHP代码执行漏洞 | |
| CVE-2011-2508 | phpMyAdmin 'Swekey_login()'目录遍历漏洞 | |
| CVE-2011-2510 | DokuWiki RSS嵌入跨站脚本攻击漏洞 | |
| CVE-2011-2526 | Apache Tomcat sendfile请求属性访问限制绕过漏洞 |
No comments yet