9.3
CVSSv2

CVE-2007-2865

Published: 25/05/2007 Updated: 29/07/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin 4.1.1 allows remote malicious users to inject arbitrary web script or HTML via the server parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phppgadmin phppgadmin 4.1.1

Vendor Advisories

Several remote vulnerabilities have been discovered in phpPgAdmin, a tool to administrate PostgreSQL database over the web The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-2865 Cross-site scripting vulnerability allows remote attackers to inject arbitrary web script or HTML via the server ...
Debian Bug report logs - #427151 CVE-2007-2865: cross-site scripting Package: phppgadmin; Maintainer for phppgadmin is Debian PostgreSQL Maintainers <team+postgresql@trackerdebianorg>; Source for phppgadmin is src:phppgadmin (PTS, buildd, popcon) Reported by: Florian Weimer <fw@denebenyode> Date: Sat, 2 Jun 2007 ...
Debian Bug report logs - #449103 CVE-2007-5728: Cross-site scripting (XSS) vulnerability Package: phppgadmin; Maintainer for phppgadmin is Debian PostgreSQL Maintainers <team+postgresql@trackerdebianorg>; Source for phppgadmin is src:phppgadmin (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeris@skolelinux ...
Debian Bug report logs - #508026 register_globals on is not supported Package: phppgadmin; Maintainer for phppgadmin is Debian PostgreSQL Maintainers <team+postgresql@trackerdebianorg>; Source for phppgadmin is src:phppgadmin (PTS, buildd, popcon) Reported by: Raphael Geissert <atomo64@gmailcom> Date: Sun, 7 Dec ...

Exploits

source: wwwsecurityfocuscom/bid/24115/info phpPgAdmin is prone to a cross-site scripting vulnerability Exploiting this vulnerability may allow an attacker to perform cross-site scripting attacks on unsuspecting users in the context of the affected website As a result, the attacker may be able to steal cookie-based authentication creden ...