|
264981
|
5.3 |
MEDIUM
Network
|
phpmyadmin opensuse
|
phpmyadmin leap opensuse
|
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to obtain sensitive information via vectors involving (1) an array value to FormDisplay.php, (…
|
CWE-200
Information Exposure
|
CVE-2016-5730
|
2024-11-21 11:54 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264982
|
7.5 |
HIGH
Network
|
phpmyadmin opensuse
|
phpmyadmin leap opensuse
|
js/get_scripts.js.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to cause a denial of service via a large array in the scripts paramet…
|
CWE-399
Resource Management Errors
|
CVE-2016-5706
|
2024-11-21 11:54 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264983
|
6.1 |
MEDIUM
Network
|
opensuse phpmyadmin
|
leap opensuse phpmyadmin
|
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) …
|
CWE-79
Cross-site Scripting
|
CVE-2016-5705
|
2024-11-21 11:54 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264984
|
6.1 |
MEDIUM
Network
|
phpmyadmin
|
phpmyadmin
|
Cross-site scripting (XSS) vulnerability in the table-structure page in phpMyAdmin 4.6.x before 4.6.3 allows remote attackers to inject arbitrary web script or HTML via vectors involving a comment.
|
CWE-79
Cross-site Scripting
|
CVE-2016-5704
|
2024-11-21 11:54 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264985
|
9.8 |
CRITICAL
Network
|
opensuse phpmyadmin
|
leap opensuse phpmyadmin
|
SQL injection vulnerability in libraries/central_columns.lib.php in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allows remote attackers to execute arbitrary SQL commands via a crafted dat…
|
CWE-89
SQL Injection
|
CVE-2016-5703
|
2024-11-21 11:54 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264986
|
3.7 |
LOW
Network
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin 4.6.x before 4.6.3, when the environment lacks a PHP_SELF value, allows remote attackers to conduct cookie-attribute injection attacks via a crafted URI.
|
CWE-254
7PK - Security Features
|
CVE-2016-5702
|
2024-11-21 11:54 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264987
|
6.1 |
MEDIUM
Network
|
phpmyadmin opensuse
|
phpmyadmin leap opensuse
|
setup/frames/index.inc.php in phpMyAdmin 4.0.10.x before 4.0.10.16, 4.4.15.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to conduct BBCode injection attacks against HTTP sessions …
|
CWE-74
Injection
|
CVE-2016-5701
|
2024-11-21 11:54 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264988
|
4.3 |
MEDIUM
Network
|
symantec
|
endpoint_protection_manager
|
Directory traversal vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to read arbitrary files in the web-root directory tree via unspe…
|
CWE-22
Path Traversal
|
CVE-2016-5307
|
2024-11-21 11:54 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264989
|
5.3 |
MEDIUM
Network
|
symantec
|
endpoint_protection_manager
|
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 does not properly implement the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information b…
|
CWE-200 CWE-254
Information Exposure 7PK - Security Features
|
CVE-2016-5306
|
2024-11-21 11:54 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264990
|
5.4 |
MEDIUM
Network
|
symantec
|
endpoint_protection_manager
|
Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow remote authenticated users to inject arbitrary web s…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5305
|
2024-11-21 11:54 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|