4.3
CVSSv2

CVE-2007-5589

Published: 19/10/2007 Updated: 17/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin prior to 2.11.1.2 allow remote malicious users to inject arbitrary web script or HTML via certain input available in (1) PHP_SELF in (a) server_status.php, and (b) grab_globals.lib.php, (c) display_change_password.lib.php, and (d) common.lib.php in libraries/; and certain input available in PHP_SELF and (2) PATH_INFO in libraries/common.inc.php. NOTE: there might also be other vectors related to (3) REQUEST_URI.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin

Vendor Advisories

Debian Bug report logs - #446451 phpmyadmin: CVE-2007-5386 XSS vulnerability Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Sat, 13 Oct 2007 05:21:02 UT ...
Omer Singer of the DigiTrust Group discovered several vulnerabilities in phpMyAdmin, an application to administrate MySQL over the WWW The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-5589 phpMyAdmin allows a remote attacker to inject arbitrary web script or HTML in the context of a logged in us ...

Exploits

source: wwwsecurityfocuscom/bid/26301/info phpMyAdmin is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This may help the attacker steal ...