Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-4326
HistorySep 30, 2008 - 12:00 a.m.

CVE-2008-4326

2008-09-3000:00:00
ubuntu.com
ubuntu.com
18

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.004

Percentile

74.3%

The PMA_escapeJsString function in libraries/js_escape.lib.php in
phpMyAdmin before 2.11.9.2, when Internet Explorer is used, allows remote
attackers to bypass cross-site scripting (XSS) protection mechanisms and
conduct XSS attacks via a NUL byte inside a “</script” sequence.

OSVersionArchitecturePackageVersionFilename
ubuntu8.04noarchphpmyadmin< 4:2.11.3-1ubuntu1.2UNKNOWN
ubuntu8.10noarchphpmyadmin< 4:2.11.8.1-1ubuntu0.1UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.004

Percentile

74.3%