2.6
CVSSv2

CVE-2008-3457

Published: 04/08/2008 Updated: 08/08/2017
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in setup.php in phpMyAdmin prior to 2.11.8 allows user-assisted remote malicious users to inject arbitrary web script or HTML via crafted setup arguments. NOTE: this issue can only be exploited in limited scenarios in which the attacker must be able to modify config/config.inc.php.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 2.0.3

phpmyadmin phpmyadmin 2.0.4

phpmyadmin phpmyadmin 2.10.0.1

phpmyadmin phpmyadmin 2.10.0.2

phpmyadmin phpmyadmin 2.0.5

phpmyadmin phpmyadmin 2.1

phpmyadmin phpmyadmin 2.10.01

phpmyadmin phpmyadmin 2.10.1

phpmyadmin phpmyadmin 2.11.0.0

phpmyadmin phpmyadmin 2.11.1

phpmyadmin phpmyadmin 2.11.2.2

phpmyadmin phpmyadmin 2.11.3

phpmyadmin phpmyadmin 2.11.6

phpmyadmin phpmyadmin

phpmyadmin phpmyadmin 2.0.1

phpmyadmin phpmyadmin 2.0.2

phpmyadmin phpmyadmin 2.1.2

phpmyadmin phpmyadmin 2.10.0

phpmyadmin phpmyadmin 2.10.0.0

phpmyadmin phpmyadmin 2.10.2.0

phpmyadmin phpmyadmin 2.10.3

phpmyadmin phpmyadmin 2.11.1.2

phpmyadmin phpmyadmin 2.11.2

phpmyadmin phpmyadmin 2.11.5

phpmyadmin phpmyadmin 2.11.5.0

phpmyadmin phpmyadmin 2.10.3.0

phpmyadmin phpmyadmin 2.11.0

phpmyadmin phpmyadmin 2.11.2.0

phpmyadmin phpmyadmin 2.11.2.1

phpmyadmin phpmyadmin 2.11.5.1

phpmyadmin phpmyadmin 2.11.5.2

phpmyadmin phpmyadmin 2.0

phpmyadmin phpmyadmin 2.0.0

phpmyadmin phpmyadmin 2.1.0

phpmyadmin phpmyadmin 2.1.1

phpmyadmin phpmyadmin 2.10.1.0

phpmyadmin phpmyadmin 2.10.2

phpmyadmin phpmyadmin 2.11.1.0

phpmyadmin phpmyadmin 2.11.1.1

phpmyadmin phpmyadmin 2.11.3.0

phpmyadmin phpmyadmin 2.11.4

phpmyadmin phpmyadmin 2.11.4.0

Vendor Advisories

Several remote vulnerabilities have been discovered in phpMyAdmin, a tool to administrate MySQL databases over the web The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2008-4096 Remote authenticated users could execute arbitrary code on the host running phpMyAdmin through manipulation of a script par ...