3.5
CVSSv2

CVE-2007-5977

Published: 15/11/2007 Updated: 29/07/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in db_create.php in phpMyAdmin prior to 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to inject arbitrary web script or HTML via a hex-encoded IMG element in the db parameter in a POST request, a different vulnerability than CVE-2006-6942.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin

Vendor Advisories

Debian Bug report logs - #451465 phpmyadmin: CVE-2007-5977 and CVE-2007-5976 Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Fri, 16 Nov 2007 04:21:01 UT ...