Skip to content
Commits on Source (3)
......@@ -2228,8 +2228,11 @@ CVE-2020-5506
RESERVED
CVE-2020-5505
RESERVED
CVE-2020-5504
RESERVED
CVE-2020-5504 (A SQL injection flaw has been discovered in the user accounts page. A ma...)
- phpmyadmin <unfixed>
NOTE: https://github.com/phpmyadmin/phpmyadmin/commit/c86acbf3ed49f69cf38b31879886dd5eb86b6983
NOTE: https://gist.github.com/ibennetch/4c1b701f4b766e4dd5556e8e26200b6b
NOTE: https://www.phpmyadmin.net/security/PMASA-2020-1/
CVE-2020-5503
RESERVED
CVE-2020-5502
......@@ -359644,8 +359647,7 @@ CVE-2007-4308 (The (1) aac_cfg_open and (2) aac_compat_ioctl functions in the SC
CVE-2007-4307 (Multiple cross-site scripting (XSS) vulnerabilities in Storesprite 7 a ...)
NOT-FOR-US: Storesprite
CVE-2007-4306 (Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.10 ...)
- phpmyadmin <unfixed> (unimportant)
[sarge] - phpmyadmin <not-affected>
- phpmyadmin <not-affected> (vulnerable code is not present)
NOTE: It seems that this requires knowledge of a unguessable session token.
NOTE: Confirmed by upstream. Sarge is not affected at all.
CVE-2007-4305 (Multiple race conditions in the (1) Sudo monitor mode and (2) Sysjail ...)
......@@ -371899,7 +371901,7 @@ CVE-2006-6374 (Multiple CRLF injection vulnerabilities in PhpMyAdmin 2.7.0-pl2 a
[etch] - phpmyadmin <not-affected> (not exploitable with Etch's php versions)
NOTE: not exploitable with PHP 5.1.2+ and 4.4.2+
CVE-2006-6373 (PhpMyAdmin 2.7.0-pl2 allows remote attackers to obtain sensitive infor ...)
- phpmyadmin <unfixed> (unimportant)
- phpmyadmin <not-affected> (vulnerable code is not present)
NOTE: path is known in Debian anyway
CVE-2006-6372 (Multiple cross-site scripting (XSS) vulnerabilities in pbguestbook.php ...)
NOT-FOR-US: JAB Guest Book
......@@ -387484,8 +387486,8 @@ CVE-2005-4351 (The securelevels implementation in FreeBSD 7.0 and earlier, OpenB
- linux-2.6 2.6.18-3
CVE-2005-4350 (Unspecified vulnerability in WBEM Services A.01.x before A.01.05.12 an ...)
NOT-FOR-US: WBEM Services
CVE-2005-4349
- phpmyadmin <unfixed> (unimportant)
CVE-2005-4349 (SQL injection vulnerability in server_privileges.php in phpMyAdmin 2.7 ...)
- phpmyadmin <not-affected> (vulnerable code is not present)
NOTE: Only for authenticated used, will possibly be rejected
CVE-2002-2208 (Extended Interior Gateway Routing Protocol (EIGRP), as implemented in ...)
NOT-FOR-US: IOS
......@@ -389440,7 +389442,7 @@ CVE-2005-3623 (nfs2acl.c in the Linux kernel 2.6.14.4 does not check for MAY_SAT
[sarge] - kernel-source-2.6.8 <not-affected> (Does not contain NFS ACLs)
- linux-2.6 2.6.14-7
CVE-2005-3622 (phpMyAdmin 2.7.0-beta1 and earlier allows remote attackers to obtain t ...)
- phpmyadmin <unfixed> (unimportant)
- phpmyadmin <not-affected> (vulnerable code is not present)
CVE-2005-3620 (The management interface for VMware ESX Server 2.0.x before 2.0.2 patc ...)
NOT-FOR-US: VMware ESX
CVE-2005-3619 (Cross-site scripting (XSS) vulnerability in the management interface f ...)
[08 Jan 2020] DLA-2060-1 phpmyadmin - security update
{CVE-2020-5504}
[jessie] - phpmyadmin 4:4.2.12-2+deb8u8
[06 Jan 2020] DLA-2059-1 git - security update
{CVE-2019-1348 CVE-2019-1349 CVE-2019-1352 CVE-2019-1353 CVE-2019-1387}
[jessie] - git 1:2.1.4-2.1+deb8u8
......