Lucene search

K
freebsdFreeBSD2D2DCBB4-906C-11DC-A951-0016179B2DD5
HistoryNov 11, 2007 - 12:00 a.m.

phpmyadmin -- cross-site scripting vulnerability

2007-11-1100:00:00
vuxml.freebsd.org
28

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS

0.006

Percentile

78.4%

The DigiTrust Group reports:

When creating a new database, a malicious user can use a
client-side Web proxy to place malicious code in the db parameter of
the POST request. Since db_create.php does not properly sanitize
user-supplied input, an administrator could face a persistent XSS
attack when the database names are displayed.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchphpmyadmin<Β 2.11.2.1UNKNOWN

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS

0.006

Percentile

78.4%