CVE Database
/

CVE-2007-5589

Back to search

CVE-2007-5589

Published: Oct 19, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.11.1.2 allow remote attackers to inject arbitrary web script or HTML via certain input available in (1) PHP_SELF in (a) server_status.php, and (b) grab_globals.lib.php, (c) display_change_password.lib.php, and (d) common.lib.php in libraries/; and certain input available in PHP_SELF and (2) PATH_INFO in libraries/common.inc.php. NOTE: there might also be other vectors related to (3) REQUEST_URI.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2007-3535
vdb-entry
x_refsource_VUPEN
27246
third-party-advisory
x_refsource_SECUNIA
FEDORA-2007-2738
vendor-advisory
x_refsource_FEDORA
phpmyadmin-serverstatus-xss(37292)
vdb-entry
x_refsource_XF
27506
third-party-advisory
x_refsource_SECUNIA
26301
vdb-entry
x_refsource_BID
DSA-1403
vendor-advisory
x_refsource_DEBIAN
SUSE-SR:2008:006
vendor-advisory
x_refsource_SUSE
37939
vdb-entry
x_refsource_OSVDB
MDKSA-2007:199
vendor-advisory
x_refsource_MANDRIVA
27595
third-party-advisory
x_refsource_SECUNIA
29323
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now