Lucene search

K
ubuntucveUbuntu.comUB:CVE-2007-1395
HistoryMar 10, 2007 - 12:00 a.m.

CVE-2007-1395

2007-03-1000:00:00
ubuntu.com
ubuntu.com
17

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.08

Percentile

94.3%

Incomplete blacklist vulnerability in index.php in phpMyAdmin 2.8.0 through
2.9.2 allows remote attackers to conduct cross-site scripting (XSS) attacks
by injecting arbitrary JavaScript or HTML in a (1) db or (2) table
parameter value followed by an uppercase </SCRIPT> end tag, which bypasses
the protection against lowercase </script>.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu7.04noarchphpmyadmin< 4:2.9.1.1-2ubuntu1.1UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.08

Percentile

94.3%