QID 730124
Date Published: 2021-12-22
QID 730124: PhpMyAdmin Multiple SQL Injection Vulnerabilities (PMASA-2020-2,PMASA-2020-3,PMASA-2020-4)
PhpMyAdmin is a free software tool written in PHP and intended to handle the administration of MySQL over the Internet.
CVE-2020-10804: An SQL injection vulnerability was found in how phpMyAdmin retrieves the current username.
CVE-2020-10803: An SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results.
CVE-2020-10802: An SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions within phpMyAdmin.
Affected Versions:
phpMyAdmin versions from 4.9.x prior to 4.9.5.
phpMyAdmin versions from 5.0.x prior to 5.0.2.
QID Detection Logic (unauthenticated):
Look for vulnerable version of phpmyadmin installed.
Successful exploitation of these vulnerabilities may allows remote attackers to inject and execute arbitrary SQL code on the targeted server.
- PMASA-2020-2 -
www.phpmyadmin.net/security/PMASA-2020-2/ - PMASA-2020-3 -
www.phpmyadmin.net/security/PMASA-2020-3/ - PMASA-2020-4 -
www.phpmyadmin.net/security/PMASA-2020-4/
CVEs related to QID 730124
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PMASA-2020-2 |
|
||
| PMASA-2020-3 |
|
||
| PMASA-2020-4 |
|