4.3
CVSSv2

CVE-2005-3665

Published: 08/12/2005 Updated: 19/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin prior to 2.7.0 allow remote malicious users to inject arbitrary web script or HTML via the (1) HTTP_HOST variable and (2) various scripts in the libraries directory that handle header generation.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 2.1.1

phpmyadmin phpmyadmin 2.6.4 rc1

phpmyadmin phpmyadmin 2.2.4

phpmyadmin phpmyadmin 2.1.2

phpmyadmin phpmyadmin 2.2 pre1

phpmyadmin phpmyadmin 2.5.0

phpmyadmin phpmyadmin 2.2

phpmyadmin phpmyadmin 2.6.4 pl1

phpmyadmin phpmyadmin 2.0.4

phpmyadmin phpmyadmin 2.6.1

phpmyadmin phpmyadmin 2.6.1 pl3

phpmyadmin phpmyadmin 2.3.1

phpmyadmin phpmyadmin 2.0.2

phpmyadmin phpmyadmin 2.5.5 rc1

phpmyadmin phpmyadmin 2.6.0 pl3

phpmyadmin phpmyadmin 2.5.7 pl1

phpmyadmin phpmyadmin 2.4.0

phpmyadmin phpmyadmin 2.5.5

phpmyadmin phpmyadmin 2.5.7

phpmyadmin phpmyadmin 2.6.2 rc1

phpmyadmin phpmyadmin 2.5.6 rc1

phpmyadmin phpmyadmin 2.0.3

phpmyadmin phpmyadmin 2.6.1 pl1

phpmyadmin phpmyadmin 2.2.6

phpmyadmin phpmyadmin 2.6.0 pl1

phpmyadmin phpmyadmin 2.6.4 pl3

phpmyadmin phpmyadmin 2.5.2

phpmyadmin phpmyadmin 2.1

phpmyadmin phpmyadmin 2.0.1

phpmyadmin phpmyadmin 2.6.2

phpmyadmin phpmyadmin 2.5.1

phpmyadmin phpmyadmin 2.6.0 pl2

phpmyadmin phpmyadmin 2.2 rc2

phpmyadmin phpmyadmin 2.3.2

phpmyadmin phpmyadmin 2.5.4

phpmyadmin phpmyadmin 2.2.5

phpmyadmin phpmyadmin 2.2 rc3

phpmyadmin phpmyadmin 2.5.3

phpmyadmin phpmyadmin 2.2.2

phpmyadmin phpmyadmin 2.2.3

phpmyadmin phpmyadmin 2.5.5 rc2

phpmyadmin phpmyadmin 2.2 pre2

phpmyadmin phpmyadmin 2.6.3 pl1

phpmyadmin phpmyadmin 2.6.1 rc1

phpmyadmin phpmyadmin 2.7.0 beta1

phpmyadmin phpmyadmin 2.2 rc1

phpmyadmin phpmyadmin 2.0

phpmyadmin phpmyadmin 2.5.5 pl1

phpmyadmin phpmyadmin 2.0.5

Vendor Advisories

The phpmyadmin update in DSA 1207 introduced a regression This update corrects this flaw For completeness, please find below the original advisory text: Several remote vulnerabilities have been discovered in phpMyAdmin, a program to administrate MySQL over the web The Common Vulnerabilities and Exposures project identifies the following problem ...
Debian Bug report logs - #340438 CVE-2005-3665: Cross-site scripting by trusting potentially user-supplied input Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Piotr Roszatycki <Piotr_Roszatycki@netianetpl& ...
Debian Bug report logs - #362567 CVE-2006-1678: Multiple cross-site scripting (XSS) vulnerabilities Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Fri, 14 Apr 2006 09 ...
Debian Bug report logs - #339437 HTTP Response Splitting vulnerability Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Michal Čihař <michal@ciharcom> Date: Wed, 16 Nov 2005 10:33:02 UTC Severity: grave ...
Debian Bug report logs - #368082 phpmyadmin: CVE-2006-2417 and CVE-2006-2418: XSS Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Alec Berryman <alec@thenednet> Date: Fri, 19 May 2006 18:48:05 UTC Severi ...