Vulnerability Name: | CVE-2007-1395 (CCN-32858) | ||||||||||||||||
Assigned: | 2007-03-07 | ||||||||||||||||
Published: | 2007-03-07 | ||||||||||||||||
Updated: | 2018-10-16 | ||||||||||||||||
Summary: | Incomplete blacklist vulnerability in index.php in phpMyAdmin 2.8.0 through 2.9.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by injecting arbitrary JavaScript or HTML in a (1) db or (2) table parameter value followed by an uppercase </SCRIPT> end tag, which bypasses the protection against lowercase </script>. | ||||||||||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.1 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: CCN Type: BugTraq Mailing List, Wed Mar 07 2007 - 09:53:46 CST xss in phpmyadmin >=2.8.0 and < 2.10.0 Source: MITRE Type: CNA CVE-2007-1395 Source: OSVDB Type: UNKNOWN 35048 Source: SECUNIA Type: UNKNOWN 26733 Source: SREASON Type: UNKNOWN 2402 Source: DEBIAN Type: DSA-1370 phpmyadmin -- several vulnerabilities Source: MANDRIVA Type: UNKNOWN MDKSA-2007:199 Source: CCN Type: OSVDB ID: 35048 phpMyAdmin XSS Protection String Blacklist Bypass Source: CCN Type: phpMyAdmin Web site phpMyAdmin | MySQL Database Administration Tool | www.phpmyadmin.net Source: BUGTRAQ Type: UNKNOWN 20070307 xss in phpmyadmin >=2.8.0 and < 2.10.0 Source: DEBIAN Type: UNKNOWN DSA-1370 Source: MISC Type: Exploit, Vendor Advisory http://www.virtuax.be/advisories/Advisory2-24012007.txt Source: XF Type: UNKNOWN phpmyadmin-dbtable-xss(32858) Source: XF Type: UNKNOWN phpmyadmin-dbtable-xss(32858) | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |