Lucene search

K
cveMitreCVE-2008-4775
HistoryOct 28, 2008 - 7:46 p.m.

CVE-2008-4775

2008-10-2819:46:09
CWE-79
mitre
web.nvd.nist.gov
32
cve
2008
4775
xss
vulnerability
phpmyadmin
web script
html
nvd

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

5.5

Confidence

High

EPSS

0.008

Percentile

82.4%

Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.

Affected configurations

Nvd
Node
phpmyadminphpmyadminMatch2.11.9.2
OR
phpmyadminphpmyadminMatch3.0.0
OR
phpmyadminphpmyadminMatch3.0.1
VendorProductVersionCPE
phpmyadminphpmyadmin2.11.9.2cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.9.2:*:*:*:*:*:*:*
phpmyadminphpmyadmin3.0.0cpe:2.3:a:phpmyadmin:phpmyadmin:3.0.0:*:*:*:*:*:*:*
phpmyadminphpmyadmin3.0.1cpe:2.3:a:phpmyadmin:phpmyadmin:3.0.1:*:*:*:*:*:*:*

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

5.5

Confidence

High

EPSS

0.008

Percentile

82.4%