4.3
CVSSv2

CVE-2008-4326

Published: 30/09/2008 Updated: 08/03/2011
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The PMA_escapeJsString function in libraries/js_escape.lib.php in phpMyAdmin prior to 2.11.9.2, when Internet Explorer is used, allows remote malicious users to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via a NUL byte inside a "</script" sequence.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin

phpmyadmin phpmyadmin 2.0

phpmyadmin phpmyadmin 2.0.0

phpmyadmin phpmyadmin 2.0.1

phpmyadmin phpmyadmin 2.0.2

phpmyadmin phpmyadmin 2.0.3

phpmyadmin phpmyadmin 2.0.4

phpmyadmin phpmyadmin 2.0.5

phpmyadmin phpmyadmin 2.1

phpmyadmin phpmyadmin 2.1.0

phpmyadmin phpmyadmin 2.1.1

phpmyadmin phpmyadmin 2.1.2

phpmyadmin phpmyadmin 2.2

phpmyadmin phpmyadmin 2.2.0

phpmyadmin phpmyadmin 2.2.0 pre1

phpmyadmin phpmyadmin 2.2.0 pre2

phpmyadmin phpmyadmin 2.2.0 rc1

phpmyadmin phpmyadmin 2.2.0 rc2

phpmyadmin phpmyadmin 2.2.0 rc3

phpmyadmin phpmyadmin 2.2.2

phpmyadmin phpmyadmin 2.2.3

phpmyadmin phpmyadmin 2.2.4

phpmyadmin phpmyadmin 2.2.5

phpmyadmin phpmyadmin 2.2.6

phpmyadmin phpmyadmin 2.2.7 pl1

phpmyadmin phpmyadmin 2.2 pre1

phpmyadmin phpmyadmin 2.2 pre2

phpmyadmin phpmyadmin 2.2 rc1

phpmyadmin phpmyadmin 2.2 rc2

phpmyadmin phpmyadmin 2.2 rc3

phpmyadmin phpmyadmin 2.3.1

phpmyadmin phpmyadmin 2.3.2

phpmyadmin phpmyadmin 2.4.0

phpmyadmin phpmyadmin 2.5.0

phpmyadmin phpmyadmin 2.5.1

phpmyadmin phpmyadmin 2.5.2

phpmyadmin phpmyadmin 2.5.2 pl1

phpmyadmin phpmyadmin 2.5.3

phpmyadmin phpmyadmin 2.5.4

phpmyadmin phpmyadmin 2.5.5

phpmyadmin phpmyadmin 2.5.5 pl1

phpmyadmin phpmyadmin 2.5.5 rc1

phpmyadmin phpmyadmin 2.5.5 rc2

phpmyadmin phpmyadmin 2.5.6 rc1

phpmyadmin phpmyadmin 2.5.6 rc2

phpmyadmin phpmyadmin 2.5.7

phpmyadmin phpmyadmin 2.5.7 pl1

phpmyadmin phpmyadmin 2.6.0 pl1

phpmyadmin phpmyadmin 2.6.0 pl2

phpmyadmin phpmyadmin 2.6.0 pl3

phpmyadmin phpmyadmin 2.6.1

phpmyadmin phpmyadmin 2.6.1 pl1

phpmyadmin phpmyadmin 2.6.1 pl3

phpmyadmin phpmyadmin 2.6.1 rc1

phpmyadmin phpmyadmin 2.6.2

phpmyadmin phpmyadmin 2.6.2 dev

phpmyadmin phpmyadmin 2.6.2 pl1

phpmyadmin phpmyadmin 2.6.2 rc1

phpmyadmin phpmyadmin 2.6.3

phpmyadmin phpmyadmin 2.6.3 pl1

phpmyadmin phpmyadmin 2.6.4

phpmyadmin phpmyadmin 2.6.4 pl1

phpmyadmin phpmyadmin 2.6.4 pl2

phpmyadmin phpmyadmin 2.6.4 pl3

phpmyadmin phpmyadmin 2.6.4 pl4

phpmyadmin phpmyadmin 2.6.4 rc1

phpmyadmin phpmyadmin 2.7

phpmyadmin phpmyadmin 2.7.0

phpmyadmin phpmyadmin 2.7.0 beta1

phpmyadmin phpmyadmin 2.7.0 pl1

phpmyadmin phpmyadmin 2.7.0 pl2

phpmyadmin phpmyadmin 2.7.0 rc1

phpmyadmin phpmyadmin 2.7 pl1

phpmyadmin phpmyadmin 2.8.0

phpmyadmin phpmyadmin 2.8.0.1

phpmyadmin phpmyadmin 2.8.0.2

phpmyadmin phpmyadmin 2.8.0.3

phpmyadmin phpmyadmin 2.8.1

phpmyadmin phpmyadmin 2.8.1 dev

phpmyadmin phpmyadmin 2.8.2

phpmyadmin phpmyadmin 2.8.3

phpmyadmin phpmyadmin 2.8.4

phpmyadmin phpmyadmin 2.9

phpmyadmin phpmyadmin 2.9.0

phpmyadmin phpmyadmin 2.9.0.1

phpmyadmin phpmyadmin 2.9.0.2

phpmyadmin phpmyadmin 2.9.0.3

phpmyadmin phpmyadmin 2.9.0 beta1

phpmyadmin phpmyadmin 2.9.0 dev

phpmyadmin phpmyadmin 2.9.0 rc1

phpmyadmin phpmyadmin 2.9.1

phpmyadmin phpmyadmin 2.9.1.1

phpmyadmin phpmyadmin 2.9.1 rc1

phpmyadmin phpmyadmin 2.9.1 rc2

phpmyadmin phpmyadmin 2.9.2

phpmyadmin phpmyadmin 2.9 rc1

phpmyadmin phpmyadmin 2.10.0

phpmyadmin phpmyadmin 2.10.0.0

phpmyadmin phpmyadmin 2.10.0.1

phpmyadmin phpmyadmin 2.10.0.2

phpmyadmin phpmyadmin 2.10.1

phpmyadmin phpmyadmin 2.10.01

phpmyadmin phpmyadmin 2.10.1.0

phpmyadmin phpmyadmin 2.10.2

phpmyadmin phpmyadmin 2.10.2.0

phpmyadmin phpmyadmin 2.10.3

phpmyadmin phpmyadmin 2.10.3.0

phpmyadmin phpmyadmin 2.10.3rc1

phpmyadmin phpmyadmin 2.11.0

phpmyadmin phpmyadmin 2.11.0.0

phpmyadmin phpmyadmin 2.11.0beta1

phpmyadmin phpmyadmin 2.11.0rc1

phpmyadmin phpmyadmin 2.11.1

phpmyadmin phpmyadmin 2.11.1.0

phpmyadmin phpmyadmin 2.11.1.1

phpmyadmin phpmyadmin 2.11.1.2

phpmyadmin phpmyadmin 2.11.1rc1

phpmyadmin phpmyadmin 2.11.2

phpmyadmin phpmyadmin 2.11.2.0

phpmyadmin phpmyadmin 2.11.2.1

phpmyadmin phpmyadmin 2.11.2.2

phpmyadmin phpmyadmin 2.11.3

phpmyadmin phpmyadmin 2.11.3.0

phpmyadmin phpmyadmin 2.11.3rc1

phpmyadmin phpmyadmin 2.11.4

phpmyadmin phpmyadmin 2.11.4.0

phpmyadmin phpmyadmin 2.11.4rc1

phpmyadmin phpmyadmin 2.11.5

phpmyadmin phpmyadmin 2.11.5.0

phpmyadmin phpmyadmin 2.11.5.1

phpmyadmin phpmyadmin 2.11.5.2

phpmyadmin phpmyadmin 2.11.5rc1

phpmyadmin phpmyadmin 2.11.6

phpmyadmin phpmyadmin 2.11.6rc1

phpmyadmin phpmyadmin 2.11.7

phpmyadmin phpmyadmin 2.11.7.0

phpmyadmin phpmyadmin 2.11.8

phpmyadmin phpmyadmin 2.11.9

Vendor Advisories

Masako Oono discovered that phpMyAdmin, a web-based administration interface for MySQL, insufficiently sanitises input allowing a remote attacker to gather sensitive data through cross site scripting, provided that the user uses the Internet Explorer web browser This update also fixes a regression introduced in DSA 1641, that broke changing of the ...