Vulnerability Name:

CVE-2007-5386 (CCN-37077)

Assigned:2007-10-09
Published:2007-10-09
Updated:2018-10-15
Summary:Cross-site scripting (XSS) vulnerability in scripts/setup.php in phpMyAdmin 2.11.1, when accessed by a browser that does not URL-encode requests, allows remote attackers to inject arbitrary web script or HTML via the query string.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-79
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2007-5386

Source: OSVDB
Type: UNKNOWN
37678

Source: CONFIRM
Type: UNKNOWN
http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/branches/MAINT_2_11_1/phpMyAdmin/ChangeLog?r1=10748&r2=10747&pathrev=10748

Source: CONFIRM
Type: UNKNOWN
http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/trunk/?view=log

Source: CCN
Type: SA27173
phpMyAdmin "setup.php" Cross-Site Scripting Vulnerability

Source: SECUNIA
Type: Vendor Advisory
27173

Source: SECUNIA
Type: UNKNOWN
27506

Source: SECUNIA
Type: UNKNOWN
27595

Source: DEBIAN
Type: UNKNOWN
DSA-1403

Source: DEBIAN
Type: DSA-1403
phpmyadmin -- missing input sanitising

Source: CCN
Type: DigiTrust Group Web site
The DigiTrust Group Advisory #071009a: phpMyAdmin

Source: MISC
Type: UNKNOWN
http://www.digitrustgroup.com/advisories/TDG-advisory071009a

Source: MANDRIVA
Type: UNKNOWN
MDKSA-2007:199

Source: CCN
Type: OSVDB ID: 37678
phpMyAdmin setup.php URL XSS

Source: CCN
Type: phpMyAdmin Web site
phpMyAdmin

Source: CONFIRM
Type: UNKNOWN
http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-5

Source: BUGTRAQ
Type: UNKNOWN
20071015 about phpMyAdmin setup.php XSS vulnerability

Source: BID
Type: UNKNOWN
26020

Source: CCN
Type: BID-26020
phpMyAdmin Setup.PHP Cross-Site Scripting Vulnerability

Source: VUPEN
Type: UNKNOWN
ADV-2007-3469

Source: CONFIRM
Type: UNKNOWN
https://bugzilla.redhat.com/show_bug.cgi?id=333661

Source: XF
Type: UNKNOWN
phpmyadmin-setup-xss(37077)

Source: XF
Type: UNKNOWN
phpmyadmin-setup-xss(37077)

Source: CONFIRM
Type: UNKNOWN
https://sourceforge.net/tracker/index.php?func=detail&aid=1810629&group_id=23067&atid=377408

Source: FEDORA
Type: UNKNOWN
FEDORA-2007-2738

Vulnerable Configuration:Configuration 1:
  • cpe:/a:phpmyadmin:phpmyadmin:2.11.1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:phpmyadmin:phpmyadmin:2.11.1:*:*:*:*:*:*:*
  • AND
  • cpe:/o:debian:debian_linux:3.1:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0::x86_64:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:20433
    P
    DSA-1403-1 phpmyadmin - cross-site scripting
    2014-06-23
    oval:org.debian:def:1403
    V
    missing input sanitising
    2007-11-08
    BACK
    phpmyadmin phpmyadmin 2.11.1
    phpmyadmin phpmyadmin 2.11.1
    debian debian linux 3.1
    mandrakesoft mandrake linux corporate server 4.0
    mandrakesoft mandrake linux corporate server 4.0
    debian debian linux 4.0