5.8
CVSSv2

CVE-2006-3388

Published: 06/07/2006 Updated: 18/10/2018
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in phpMyAdmin prior to 2.8.2 allows remote malicious users to inject arbitrary web script or HTML via the table parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 2.0.1

phpmyadmin phpmyadmin 2.0.2

phpmyadmin phpmyadmin 2.2

phpmyadmin phpmyadmin 2.2.2

phpmyadmin phpmyadmin 2.2_rc1

phpmyadmin phpmyadmin 2.0.5

phpmyadmin phpmyadmin 2.1

phpmyadmin phpmyadmin 2.2.5

phpmyadmin phpmyadmin 2.2.6

phpmyadmin phpmyadmin 2.3.2

phpmyadmin phpmyadmin 2.4.0

phpmyadmin phpmyadmin 2.5.5_rc1

phpmyadmin phpmyadmin 2.5.5_rc2

phpmyadmin phpmyadmin 2.6.1

phpmyadmin phpmyadmin 2.6.1_pl1

phpmyadmin phpmyadmin 2.6.4_pl3

phpmyadmin phpmyadmin 2.6.4_pl4

phpmyadmin phpmyadmin 2.6.4_rc1

phpmyadmin phpmyadmin 2.2_rc2

phpmyadmin phpmyadmin 2.5.3

phpmyadmin phpmyadmin 2.5.4

phpmyadmin phpmyadmin 2.5.7_pl1

phpmyadmin phpmyadmin 2.6.0_pl1

phpmyadmin phpmyadmin 2.6.2

phpmyadmin phpmyadmin 2.6.2_rc1

phpmyadmin phpmyadmin 2.7_pl1

phpmyadmin phpmyadmin 2.8.1

phpmyadmin phpmyadmin 2.0

phpmyadmin phpmyadmin 2.1.1

phpmyadmin phpmyadmin 2.1.2

phpmyadmin phpmyadmin 2.2_pre1

phpmyadmin phpmyadmin 2.2_pre2

phpmyadmin phpmyadmin 2.5.0

phpmyadmin phpmyadmin 2.5.1

phpmyadmin phpmyadmin 2.5.2

phpmyadmin phpmyadmin 2.5.6_rc1

phpmyadmin phpmyadmin 2.5.7

phpmyadmin phpmyadmin 2.6.1_pl3

phpmyadmin phpmyadmin 2.6.1_rc1

phpmyadmin phpmyadmin 2.7

phpmyadmin phpmyadmin 2.7.0_beta1

phpmyadmin phpmyadmin 2.0.3

phpmyadmin phpmyadmin 2.0.4

phpmyadmin phpmyadmin 2.2.3

phpmyadmin phpmyadmin 2.2.4

phpmyadmin phpmyadmin 2.2_rc3

phpmyadmin phpmyadmin 2.3.1

phpmyadmin phpmyadmin 2.5.5

phpmyadmin phpmyadmin 2.5.5_pl1

phpmyadmin phpmyadmin 2.6.0_pl2

phpmyadmin phpmyadmin 2.6.0_pl3

phpmyadmin phpmyadmin 2.6.3_pl1

phpmyadmin phpmyadmin 2.6.4_pl1

phpmyadmin phpmyadmin 2.8.3

phpmyadmin phpmyadmin 2.8.4

Vendor Advisories

Debian Bug report logs - #368082 phpmyadmin: CVE-2006-2417 and CVE-2006-2418: XSS Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Alec Berryman <alec@thenednet> Date: Fri, 19 May 2006 18:48:05 UTC Severi ...
Debian Bug report logs - #339437 HTTP Response Splitting vulnerability Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Michal Čihař <michal@ciharcom> Date: Wed, 16 Nov 2005 10:33:02 UTC Severity: grave ...
Debian Bug report logs - #362567 CVE-2006-1678: Multiple cross-site scripting (XSS) vulnerabilities Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Fri, 14 Apr 2006 09 ...
Debian Bug report logs - #391090 phpmyadmin: security issue PMASA-2006-5 Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Laurent Bonnaud <LaurentBonnaud@inpgfr> Date: Wed, 4 Oct 2006 20:33:02 UTC Sever ...
Debian Bug report logs - #340438 CVE-2005-3665: Cross-site scripting by trusting potentially user-supplied input Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Piotr Roszatycki <Piotr_Roszatycki@netianetpl& ...
Debian Bug report logs - #377748 phpmyadmin: CVE-2006-3388: cross-site scripting Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Alec Berryman <alec@thenednet> Date: Tue, 11 Jul 2006 01:33:05 UTC Severit ...