Vulnerability Name: | CVE-2008-4775 (CCN-46136) | ||||||||
Assigned: | 2008-10-27 | ||||||||
Published: | 2008-10-27 | ||||||||
Updated: | 2018-10-11 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N) 2.2 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Mon Oct 27 2008 - 07:02:51 CDT XSS in phpMyadmin Source: MITRE Type: CNA CVE-2008-4775 Source: CCN Type: gmane Mailing List, Hanno Böck | 27 Oct 23:26 CVE request phpmyadmin (Fwd: XSS in phpMyadmin) Source: CCN Type: SA32449 phpMyAdmin "db" Cross-Site Scripting Vulnerability Source: SECUNIA Type: Vendor Advisory 32449 Source: SECUNIA Type: Vendor Advisory 32482 Source: CCN Type: SA32654 TYPO3 phpMyAdmin Extension "db" Cross-Site Scripting Vulnerability Source: GENTOO Type: UNKNOWN GLSA-200903-32 Source: SREASON Type: UNKNOWN 4516 Source: CCN Type: TYPO3 Extension Repository phpMyAdmin Source: CCN Type: TYPO3-20081110-1 Cross-Site Scripting vulnerability in extension phpMyAdmin (phpmyadmin) Source: CCN Type: GLSA-200903-32 phpMyAdmin: Multiple vulnerabilities Source: CCN Type: OSVDB ID: 49692 TYPO3 phpMyAdmin Extension pmd_pdf.php db Parameter XSS Source: CCN Type: phpMyAdmin Web site phpMyAdmin Source: CCN Type: phpMyAdmin security announcement PMASA-2008-9 XSS on a Designer component Source: BUGTRAQ Type: UNKNOWN 20081027 XSS in phpMyadmin Source: BID Type: UNKNOWN 31928 Source: CCN Type: BID-31928 phpMyAdmin 'pmd_pdf.php' Cross Site Scripting Vulnerability Source: VUPEN Type: UNKNOWN ADV-2008-2943 Source: XF Type: UNKNOWN phpmyadmin-pmdpdf-xss(46136) Source: XF Type: UNKNOWN phpmyadmin-pmdpdf-xss(46136) Source: FEDORA Type: UNKNOWN FEDORA-2008-9316 Source: FEDORA Type: UNKNOWN FEDORA-2008-9336 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |