4.3
CVSSv2

CVE-2009-1150

Published: 26/03/2009 Updated: 15/07/2009
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in the export page (display_export.lib.php) in phpMyAdmin 2.11.x prior to 2.11.9.5 and 3.x prior to 3.1.3.1 allow remote malicious users to inject arbitrary web script or HTML via the pma_db_filename_template cookie.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 3.1.3

phpmyadmin phpmyadmin 3.1.2

phpmyadmin phpmyadmin 3.1.1

phpmyadmin phpmyadmin 2.11.6.0

phpmyadmin phpmyadmin 2.11.6

phpmyadmin phpmyadmin 2.11.5

phpmyadmin phpmyadmin 2.11.5.2

phpmyadmin phpmyadmin 2.11.1.2

phpmyadmin phpmyadmin 2.11.1.1

phpmyadmin phpmyadmin 2.11.1.0

phpmyadmin phpmyadmin 2.11.1

phpmyadmin phpmyadmin 2.11.9.2

phpmyadmin phpmyadmin 2.11.9.1

phpmyadmin phpmyadmin 2.11.9.0

phpmyadmin phpmyadmin 2.11.9

phpmyadmin phpmyadmin 2.11.3

phpmyadmin phpmyadmin 2.11.3.0

phpmyadmin phpmyadmin 2.11.2.2

phpmyadmin phpmyadmin 2.11.9.3

phpmyadmin phpmyadmin 2.11.7.0

phpmyadmin phpmyadmin 2.11.5.1

phpmyadmin phpmyadmin 2.11.4

phpmyadmin phpmyadmin 2.11.2.1

phpmyadmin phpmyadmin 2.11.2

phpmyadmin phpmyadmin 2.11.0

phpmyadmin phpmyadmin 3.1.0

phpmyadmin phpmyadmin 2.11.9.4

phpmyadmin phpmyadmin 2.11.8

phpmyadmin phpmyadmin 2.11.7

phpmyadmin phpmyadmin 2.11.5.0

phpmyadmin phpmyadmin 2.11.2.0

Vendor Advisories

Several remote vulnerabilities have been discovered in phpMyAdmin, a tool to administer MySQL over the web The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-1150 Cross site scripting vulnerability in the export page allow for an attacker that can place crafted cookies with the user to inject arbitr ...