6.5
CVSSv2

CVE-2007-5976

Published: 15/11/2007 Updated: 29/07/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in db_create.php in phpMyAdmin prior to 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to execute arbitrary SQL commands via the db parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin

Vendor Advisories

Debian Bug report logs - #451465 phpmyadmin: CVE-2007-5977 and CVE-2007-5976 Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Fri, 16 Nov 2007 04:21:01 UT ...