5
CVSSv2

CVE-2005-3621

Published: 16/11/2005 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

CRLF injection vulnerability in phpMyAdmin prior to 2.6.4-pl4 allows remote malicious users to conduct HTTP response splitting attacks via unspecified scripts.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 2.5.3

phpmyadmin phpmyadmin 2.5.5_pl1

phpmyadmin phpmyadmin 2.6.4_pl3

phpmyadmin phpmyadmin 2.2.0

phpmyadmin phpmyadmin 2.2.7_pl1

phpmyadmin phpmyadmin 2.5.2_pl1

phpmyadmin phpmyadmin 2.5.7_pl1

phpmyadmin phpmyadmin 2.6.0_pl3

phpmyadmin phpmyadmin 2.6.1_pl3

phpmyadmin phpmyadmin 2.6.2_pl1

phpmyadmin phpmyadmin 2.5.4

phpmyadmin phpmyadmin 2.5.6_rc2

phpmyadmin phpmyadmin 2.6.3_pl1

Vendor Advisories

The phpmyadmin update in DSA 1207 introduced a regression This update corrects this flaw For completeness, please find below the original advisory text: Several remote vulnerabilities have been discovered in phpMyAdmin, a program to administrate MySQL over the web The Common Vulnerabilities and Exposures project identifies the following problem ...
Debian Bug report logs - #368082 phpmyadmin: CVE-2006-2417 and CVE-2006-2418: XSS Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Alec Berryman <alec@thenednet> Date: Fri, 19 May 2006 18:48:05 UTC Severi ...
Debian Bug report logs - #339437 HTTP Response Splitting vulnerability Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Michal Čihař <michal@ciharcom> Date: Wed, 16 Nov 2005 10:33:02 UTC Severity: grave ...
Debian Bug report logs - #362567 CVE-2006-1678: Multiple cross-site scripting (XSS) vulnerabilities Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Fri, 14 Apr 2006 09 ...
Debian Bug report logs - #340438 CVE-2005-3665: Cross-site scripting by trusting potentially user-supplied input Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Piotr Roszatycki <Piotr_Roszatycki@netianetpl& ...