Mysqldumper
Mysqldumper: vulnerabilidades y CVE
Mysqldumper tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2017-1000012 | Media (6.1) | 0.76% | — | 17 jul 2017 | MySQL Dumper version 1.24 is vulnerable to stored XSS when displaying the data in the database to the user |
| CVE-2012-4255 | Media (4.3) | 1.3% | — | 13 ago 2012 | MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information via a direct request to learn/cubemail/refresh_dblist.php, which reveals the installation path in an error message. |
| CVE-2012-4254 | Media (4.3) | 2.4% | — | 13 ago 2012 | MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information (Notices) via a direct request to (1) learn/cubemail/restore.php or (2) learn/cubemail/dump.php. |
| CVE-2012-4253 | Media (4.3) | 8.5% | — | 13 ago 2012 | Multiple directory traversal vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) language parameter to learn/cubemail/install.php or (2) f parameter… |
| CVE-2012-4252 | Media (5.1) | 1.1% | — | 13 ago 2012 | Multiple cross-site request forgery (CSRF) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to hijack the authentication of administrators for requests that (1) remove file access restriction via a… |
| CVE-2012-4251 | Media (4.3) | 1.9% | — | 13 ago 2012 | Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to index.php, (2) phase parameter to install.php, (3)… |
| CVE-2007-3567 | Alta (7.5) | 2.8% | — | 5 jul 2007 | MySQLDumper 1.21b through 1.23 REV227 uses a "Limit GET" statement in the .htaccess authentication mechanism, which allows remote attackers to bypass authentication requirements via HTTP POST requests. |
| CVE-2006-5264 | Media (6.8) | 1.3% | — | 12 oct 2006 | Cross-site scripting (XSS) vulnerability in sql.php in MysqlDumper 1.21 b6 allows remote attackers to inject arbitrary web script or HTML via the db parameter. |