|
265241
|
5.3 |
MEDIUM
Network
|
phpmyadmin
|
phpmyadmin
|
An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to bypass the logout timeout. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) …
|
CWE-254
7PK - Security Features
|
CVE-2016-9851
|
2024-11-21 12:01 |
2016-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265242
|
5.3 |
MEDIUM
Network
|
phpmyadmin
|
phpmyadmin
|
An issue was discovered in phpMyAdmin. Username matching for the allow/deny rules may result in wrong matches and detection of the username in the rule due to non-constant execution time. All 4.6.x v…
|
CWE-254
7PK - Security Features
|
CVE-2016-9850
|
2024-11-21 12:01 |
2016-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265243
|
9.8 |
CRITICAL
Network
|
phpmyadmin
|
phpmyadmin
|
An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restriction ($cfg['Servers'][$i]['AllowRoot']) and deny rules for username by using Null Byte in the username. All 4.6.x vers…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9849
|
2024-11-21 12:01 |
2016-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265244
|
5.3 |
MEDIUM
Network
|
phpmyadmin
|
phpmyadmin
|
An issue was discovered in phpMyAdmin. phpinfo (phpinfo.php) shows PHP information including values of HttpOnly cookies. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4…
|
CWE-200
Information Exposure
|
CVE-2016-9848
|
2024-11-21 12:01 |
2016-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265245
|
5.3 |
MEDIUM
Network
|
phpmyadmin
|
phpmyadmin
|
An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the…
|
CWE-200
Information Exposure
|
CVE-2016-9853
|
2024-11-21 12:01 |
2016-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265246
|
5.3 |
MEDIUM
Network
|
phpmyadmin
|
phpmyadmin
|
An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the…
|
CWE-200
Information Exposure
|
CVE-2016-9852
|
2024-11-21 12:01 |
2016-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265247
|
5.3 |
MEDIUM
Network
|
phpmyadmin
|
phpmyadmin
|
An issue was discovered in phpMyAdmin. When the user does not specify a blowfish_secret key for encrypting cookies, phpMyAdmin generates one at runtime. A vulnerability was reported where the way thi…
|
CWE-310
Cryptographic Issues
|
CVE-2016-9847
|
2024-11-21 12:01 |
2016-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265248
|
9.9 |
CRITICAL
Network
|
pwc
|
ace-advanced_business_application_programming
|
PricewaterhouseCoopers (PwC) ACE-ABAP 8.10.304 for SAP Security allows remote authenticated users to conduct ABAP injection attacks and execute arbitrary code via (1) SAPGUI or (2) Internet Communica…
|
CWE-74
Injection
|
CVE-2016-9832
|
2024-11-21 12:01 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265249
|
5.5 |
MEDIUM
Local
|
gnome
|
libgsf
|
An error within the "tar_directory_for_file()" function (gsf-infile-tar.c) in GNOME Structured File Library before 1.14.41 can be exploited to trigger a Null pointer dereference and subsequently caus…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-9888
|
2024-11-21 12:01 |
2016-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265250
|
7.5 |
HIGH
Network
|
osgeo
|
mapserver
|
In MapServer before 7.0.3, OGR driver error messages are too verbose and may leak sensitive information if data connection fails.
|
CWE-200
Information Exposure
|
CVE-2016-9839
|
2024-11-21 12:01 |
2016-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|