4.3
CVSSv2

CVE-2013-1937

Published: 16/04/2013 Updated: 11/04/2024
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x prior to 3.5.8 might allow remote malicious users to inject arbitrary web script or HTML via the (1) visualizationSettings[width] or (2) visualizationSettings[height] parameter. NOTE: a third party reports that this is "not exploitable.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 3.5.4

phpmyadmin phpmyadmin 3.5.2.2

phpmyadmin phpmyadmin 3.5.6

phpmyadmin phpmyadmin 3.5.5

phpmyadmin phpmyadmin 3.5.1.0

phpmyadmin phpmyadmin 3.5.7

phpmyadmin phpmyadmin 3.5.3.0

phpmyadmin phpmyadmin 3.5.2.1

phpmyadmin phpmyadmin 3.5.2.0

phpmyadmin phpmyadmin 3.5.0.0

phpmyadmin phpmyadmin

Exploits

source: wwwsecurityfocuscom/bid/58962/info phpMyAdmin is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This can allow th ...

Github Repositories

Common Vulnerability Scoring System Version 3

Common Vulnerability Scoring System Version 3 Usage Demo code (appjs) : var cvss3 = require('cvss3'); var vector_cve_2013_1937 = "CVSS:30/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"; var vector_temporal_x = "E:X/RL:X/RC:X"; var vector_env_x = "CR:X/IR:X/AR:X/MAV:X/MAC:X/MPR:X/MUI:X/MS:X/MC:X/MI:X/MA:X"; var vector_full = vector_cve_2013_1