CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
Percentile
87.1%
A phpMyAdmin security advisory reports:
It was possible to conduct an XSS attack via the
HTTP_HOST variable; also, some scripts in the libraries
directory that handle header generation were vulnerable
to XSS.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
FreeBSD | any | noarch | phpmyadmin | < 2.7.0 | UNKNOWN |