ALT-PU-2020-3037-1
Package phpMyAdmin updated to version 5.0.3-alt1 for branch sisyphus in task 259829.
Closed vulnerabilities
BDU:2021-01804
Уязвимость функции «Export» веб-приложения для администрирования систем управления базами данных phpMyAdmin, позволяющая нарушителю выполнить произвольный код
BDU:2021-01859
Уязвимость реализации класса SearchController веб-приложения для администрирования систем управления базами данных phpMyAdmin, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01860
Уязвимость реализации функции преобразования веб-приложения для администрирования систем управления базами данных phpMyAdmin, позволяющая нарушителю осуществлять межсайтовые сценарные атаки
Modified: 2024-11-21
CVE-2020-11441
phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable.
Modified: 2024-11-21
CVE-2020-22278
phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.
- https://cert.ikiu.ac.ir/public-files/news/document/CVE-99/CVE-2020-22278.pdf
- https://cert.ikiu.ac.ir/public-files/news/document/CVE-99/CVE-2020-22278.pdf
- https://mega.nz/file/ySQnlQSR#vXzY46mgf0CE2ysYpWpbE4O6T_g37--rtaL8pqdHcQs
- https://mega.nz/file/ySQnlQSR#vXzY46mgf0CE2ysYpWpbE4O6T_g37--rtaL8pqdHcQs
Modified: 2024-11-21
CVE-2020-26934
phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.
- openSUSE-SU-2020:1675
- openSUSE-SU-2020:1675
- openSUSE-SU-2020:1806
- openSUSE-SU-2020:1806
- [debian-lts-announce] 20201025 [SECURITY] [DLA 2413-1] phpmyadmin security update
- [debian-lts-announce] 20201025 [SECURITY] [DLA 2413-1] phpmyadmin security update
- FEDORA-2020-43d8624421
- FEDORA-2020-43d8624421
- FEDORA-2020-eadda524a8
- FEDORA-2020-eadda524a8
- FEDORA-2020-4e78c86902
- FEDORA-2020-4e78c86902
- GLSA-202101-35
- GLSA-202101-35
- https://www.phpmyadmin.net/security/PMASA-2020-5/
- https://www.phpmyadmin.net/security/PMASA-2020-5/
Modified: 2024-11-21
CVE-2020-26935
An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.
- openSUSE-SU-2020:1675
- openSUSE-SU-2020:1675
- openSUSE-SU-2020:1806
- openSUSE-SU-2020:1806
- https://advisory.checkmarx.net/advisory/CX-2020-4281
- https://advisory.checkmarx.net/advisory/CX-2020-4281
- [debian-lts-announce] 20201025 [SECURITY] [DLA 2413-1] phpmyadmin security update
- [debian-lts-announce] 20201025 [SECURITY] [DLA 2413-1] phpmyadmin security update
- FEDORA-2020-43d8624421
- FEDORA-2020-43d8624421
- FEDORA-2020-eadda524a8
- FEDORA-2020-eadda524a8
- FEDORA-2020-4e78c86902
- FEDORA-2020-4e78c86902
- GLSA-202101-35
- GLSA-202101-35
- https://www.phpmyadmin.net/security/PMASA-2020-6/
- https://www.phpmyadmin.net/security/PMASA-2020-6/