4.3
CVSSv2

CVE-2008-4326

Published: 30/09/2008 Updated: 08/03/2011
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The PMA_escapeJsString function in libraries/js_escape.lib.php in phpMyAdmin prior to 2.11.9.2, when Internet Explorer is used, allows remote malicious users to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via a NUL byte inside a "</script" sequence.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 2.0.3

phpmyadmin phpmyadmin 2.0.0

phpmyadmin phpmyadmin 2.10.0

phpmyadmin phpmyadmin 2.10.1

phpmyadmin phpmyadmin 2.10.1.0

phpmyadmin phpmyadmin 2.11.1.0

phpmyadmin phpmyadmin 2.11.0beta1

phpmyadmin phpmyadmin 2.11.0.0

phpmyadmin phpmyadmin 2.11.1rc1

phpmyadmin phpmyadmin 2.11.3rc1

phpmyadmin phpmyadmin 2.11.5rc1

phpmyadmin phpmyadmin 2.11.4rc1

phpmyadmin phpmyadmin 2.11.8

phpmyadmin phpmyadmin

phpmyadmin phpmyadmin 2.2_rc1

phpmyadmin phpmyadmin 2.2_pre2

phpmyadmin phpmyadmin 2.2_pre1

phpmyadmin phpmyadmin 2.2.7_pl1

phpmyadmin phpmyadmin 2.5.1

phpmyadmin phpmyadmin 2.5.2

phpmyadmin phpmyadmin 2.5.5_rc2

phpmyadmin phpmyadmin 2.5.5_rc1

phpmyadmin phpmyadmin 2.6.1

phpmyadmin phpmyadmin 2.1.0

phpmyadmin phpmyadmin 2.0.4

phpmyadmin phpmyadmin 2.10.0.2

phpmyadmin phpmyadmin 2.10.0.1

phpmyadmin phpmyadmin 2.10.3

phpmyadmin phpmyadmin 2.10.2.0

phpmyadmin phpmyadmin 2.11.2.0

phpmyadmin phpmyadmin 2.11.1.2

phpmyadmin phpmyadmin 2.11.5.2

phpmyadmin phpmyadmin 2.11.6

phpmyadmin phpmyadmin 2.11.5.1

phpmyadmin phpmyadmin 2.11.5

phpmyadmin phpmyadmin 2.2.0

phpmyadmin phpmyadmin 2.2.0_pre1

phpmyadmin phpmyadmin 2.2.0_pre2

phpmyadmin phpmyadmin 2.2.3

phpmyadmin phpmyadmin 2.2.4

phpmyadmin phpmyadmin 2.2_rc3

phpmyadmin phpmyadmin 2.4.0

phpmyadmin phpmyadmin 2.5.7_pl1

phpmyadmin phpmyadmin 2.5.7

phpmyadmin phpmyadmin 2.5.4

phpmyadmin phpmyadmin 2.6.0_pl3

phpmyadmin phpmyadmin 2.7

phpmyadmin phpmyadmin 2.6.4_pl4

phpmyadmin phpmyadmin 2.6.4_rc1

phpmyadmin phpmyadmin 2.7.0_beta1

phpmyadmin phpmyadmin 2.7_pl1

phpmyadmin phpmyadmin 2.8.0

phpmyadmin phpmyadmin 2.7.0_rc1

phpmyadmin phpmyadmin 2.9.0.3

phpmyadmin phpmyadmin 2.9.0.1

phpmyadmin phpmyadmin 2.9.1_rc2

phpmyadmin phpmyadmin 2.9.0_dev

phpmyadmin phpmyadmin 2.0.2

phpmyadmin phpmyadmin 2.0.5

phpmyadmin phpmyadmin 2.0

phpmyadmin phpmyadmin 2.10.2

phpmyadmin phpmyadmin 2.10.0.0

phpmyadmin phpmyadmin 2.10.01

phpmyadmin phpmyadmin 2.10.3rc1

phpmyadmin phpmyadmin 2.10.3.0

phpmyadmin phpmyadmin 2.11.1.1

phpmyadmin phpmyadmin 2.11.2.1

phpmyadmin phpmyadmin 2.11.3.0

phpmyadmin phpmyadmin 2.11.6rc1

phpmyadmin phpmyadmin 2.11.4

phpmyadmin phpmyadmin 2.11.7

phpmyadmin phpmyadmin 2.11.7.0

phpmyadmin phpmyadmin 2.2.0_rc1

phpmyadmin phpmyadmin 2.2.0_rc2

phpmyadmin phpmyadmin 2.2.5

phpmyadmin phpmyadmin 2.2.6

phpmyadmin phpmyadmin 2.2_rc2

phpmyadmin phpmyadmin 2.5.0

phpmyadmin phpmyadmin 2.5.6_rc2

phpmyadmin phpmyadmin 2.5.6_rc1

phpmyadmin phpmyadmin 2.6.1_pl3

phpmyadmin phpmyadmin 2.6.1_pl1

phpmyadmin phpmyadmin 2.6.2_dev

phpmyadmin phpmyadmin 2.7.0

phpmyadmin phpmyadmin 2.6.1_rc1

phpmyadmin phpmyadmin 2.6.2_rc1

phpmyadmin phpmyadmin 2.6.2

phpmyadmin phpmyadmin 2.6.4

phpmyadmin phpmyadmin 2.6.4_pl1

phpmyadmin phpmyadmin 2.8.1

phpmyadmin phpmyadmin 2.8.0.3

phpmyadmin phpmyadmin 2.9.0

phpmyadmin phpmyadmin 2.8.2

phpmyadmin phpmyadmin 2.9.1.1

phpmyadmin phpmyadmin 2.9.2

phpmyadmin phpmyadmin 2.6.3

phpmyadmin phpmyadmin 2.6.3_pl1

phpmyadmin phpmyadmin 2.7.0_pl2

phpmyadmin phpmyadmin 2.7.0_pl1

phpmyadmin phpmyadmin 2.8.1_dev

phpmyadmin phpmyadmin 2.8.4

phpmyadmin phpmyadmin 2.8.3

phpmyadmin phpmyadmin 2.9.1

phpmyadmin phpmyadmin 2.9.1_rc1

phpmyadmin phpmyadmin 2.0.1

phpmyadmin phpmyadmin 2.1

phpmyadmin phpmyadmin 2.1.2

phpmyadmin phpmyadmin 2.1.1

phpmyadmin phpmyadmin 2.11.1

phpmyadmin phpmyadmin 2.11.0

phpmyadmin phpmyadmin 2.11.0rc1

phpmyadmin phpmyadmin 2.11.2.2

phpmyadmin phpmyadmin 2.11.3

phpmyadmin phpmyadmin 2.11.2

phpmyadmin phpmyadmin 2.11.5.0

phpmyadmin phpmyadmin 2.11.4.0

phpmyadmin phpmyadmin 2.11.9

phpmyadmin phpmyadmin 2.2

phpmyadmin phpmyadmin 2.2.0_rc3

phpmyadmin phpmyadmin 2.2.2

phpmyadmin phpmyadmin 2.3.1

phpmyadmin phpmyadmin 2.3.2

phpmyadmin phpmyadmin 2.5.2_pl1

phpmyadmin phpmyadmin 2.5.3

phpmyadmin phpmyadmin 2.6.0_pl1

phpmyadmin phpmyadmin 2.5.5_pl1

phpmyadmin phpmyadmin 2.5.5

phpmyadmin phpmyadmin 2.6.0_pl2

phpmyadmin phpmyadmin 2.6.2_pl1

phpmyadmin phpmyadmin 2.6.4_pl2

phpmyadmin phpmyadmin 2.6.4_pl3

phpmyadmin phpmyadmin 2.8.0.2

phpmyadmin phpmyadmin 2.8.0.1

phpmyadmin phpmyadmin 2.9

phpmyadmin phpmyadmin 2.9.0_beta1

phpmyadmin phpmyadmin 2.9.0.2

phpmyadmin phpmyadmin 2.9_rc1

phpmyadmin phpmyadmin 2.9.0_rc1

Vendor Advisories

Masako Oono discovered that phpMyAdmin, a web-based administration interface for MySQL, insufficiently sanitises input allowing a remote attacker to gather sensitive data through cross site scripting, provided that the user uses the Internet Explorer web browser This update also fixes a regression introduced in DSA 1641, that broke changing of the ...