6.8
CVSSv2

CVE-2006-6942

Published: 19/01/2007 Updated: 29/07/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 700
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin prior to 2.9.1.1 allow remote malicious users to inject arbitrary HTML or web script via (1) a comment for a table name, as exploited through (a) db_operations.php, (2) the db parameter to (b) db_create.php, (3) the newname parameter to db_operations.php, the (4) query_history_latest, (5) query_history_latest_db, and (6) querydisplay_tab parameters to (c) querywindow.php, and (7) the pos parameter to (d) sql.php.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 2.9.0

phpmyadmin phpmyadmin 2.9.1_rc2

phpmyadmin phpmyadmin

phpmyadmin phpmyadmin 2.9.0.1

phpmyadmin phpmyadmin 2.9.0.2

phpmyadmin phpmyadmin 2.9.0_rc1

phpmyadmin phpmyadmin 2.9.1_rc1

phpmyadmin phpmyadmin 2.9.0.3

phpmyadmin phpmyadmin 2.9.0_beta1

debian debian linux 4.0

debian debian linux 3.1

Vendor Advisories

Debian Bug report logs - #451465 phpmyadmin: CVE-2007-5977 and CVE-2007-5976 Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Fri, 16 Nov 2007 04:21:01 UT ...

Exploits

source: wwwsecurityfocuscom/bid/21137/info phpMyAdmin is prone to multiple input-validation vulnerabilities, including an HTML-injection vulnerability, cross-site scripting vulnerabilities, and information-disclosure vulnerabilities An attacker could exploit these vulnerabilities to view sensitive information or to have arbitrary sc ...
source: wwwsecurityfocuscom/bid/21137/info phpMyAdmin is prone to multiple input-validation vulnerabilities, including an HTML-injection vulnerability, cross-site scripting vulnerabilities, and information-disclosure vulnerabilities An attacker could exploit these vulnerabilities to view sensitive information or to have arbitrary ...
source: wwwsecurityfocuscom/bid/21137/info phpMyAdmin is prone to multiple input-validation vulnerabilities, including an HTML-injection vulnerability, cross-site scripting vulnerabilities, and information-disclosure vulnerabilities An attacker could exploit these vulnerabilities to view sensitive information or to have arbitrary script ...
source: wwwsecurityfocuscom/bid/21137/info phpMyAdmin is prone to multiple input-validation vulnerabilities, including an HTML-injection vulnerability, cross-site scripting vulnerabilities, and information-disclosure vulnerabilities An attacker could exploit these vulnerabilities to view sensitive information or to have arbitrary scri ...