4.3
CVSSv2

CVE-2007-5386

Published: 12/10/2007 Updated: 15/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in scripts/setup.php in phpMyAdmin 2.11.1, when accessed by a browser that does not URL-encode requests, allows remote malicious users to inject arbitrary web script or HTML via the query string.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 2.11.1

Vendor Advisories

Debian Bug report logs - #446451 phpmyadmin: CVE-2007-5386 XSS vulnerability Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Sat, 13 Oct 2007 05:21:02 UT ...
Omer Singer of the DigiTrust Group discovered several vulnerabilities in phpMyAdmin, an application to administrate MySQL over the WWW The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-5589 phpMyAdmin allows a remote attacker to inject arbitrary web script or HTML in the context of a logged in us ...

Exploits

source: wwwsecurityfocuscom/bid/26020/info phpMyAdmin is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This may help the attacker steal ...