CVE Vulnerabilities

CVE-2007-1395

Published: Mar 10, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Incomplete blacklist vulnerability in index.php in phpMyAdmin 2.8.0 through 2.9.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by injecting arbitrary JavaScript or HTML in a (1) db or (2) table parameter value followed by an uppercase end tag, which bypasses the protection against lowercase .

Affected Software

Name Vendor Start Version End Version
Phpmyadmin Phpmyadmin 2.8.0 (including) 2.8.0 (including)
Phpmyadmin Phpmyadmin 2.8.0.1 (including) 2.8.0.1 (including)
Phpmyadmin Phpmyadmin 2.8.0.2 (including) 2.8.0.2 (including)
Phpmyadmin Phpmyadmin 2.8.0.3 (including) 2.8.0.3 (including)
Phpmyadmin Phpmyadmin 2.8.1 (including) 2.8.1 (including)
Phpmyadmin Phpmyadmin 2.8.1_dev (including) 2.8.1_dev (including)
Phpmyadmin Phpmyadmin 2.8.2 (including) 2.8.2 (including)
Phpmyadmin Phpmyadmin 2.8.3 (including) 2.8.3 (including)
Phpmyadmin Phpmyadmin 2.8.4 (including) 2.8.4 (including)
Phpmyadmin Phpmyadmin 2.9 (including) 2.9 (including)
Phpmyadmin Phpmyadmin 2.9.0 (including) 2.9.0 (including)
Phpmyadmin Phpmyadmin 2.9.0.1 (including) 2.9.0.1 (including)
Phpmyadmin Phpmyadmin 2.9.0.2 (including) 2.9.0.2 (including)
Phpmyadmin Phpmyadmin 2.9.0.3 (including) 2.9.0.3 (including)
Phpmyadmin Phpmyadmin 2.9.0_beta1 (including) 2.9.0_beta1 (including)
Phpmyadmin Phpmyadmin 2.9.0_dev (including) 2.9.0_dev (including)
Phpmyadmin Phpmyadmin 2.9.0_rc1 (including) 2.9.0_rc1 (including)
Phpmyadmin Phpmyadmin 2.9.1 (including) 2.9.1 (including)
Phpmyadmin Phpmyadmin 2.9.1.1 (including) 2.9.1.1 (including)
Phpmyadmin Phpmyadmin 2.9.1_rc1 (including) 2.9.1_rc1 (including)
Phpmyadmin Phpmyadmin 2.9.1_rc2 (including) 2.9.1_rc2 (including)
Phpmyadmin Phpmyadmin 2.9.2 (including) 2.9.2 (including)
Phpmyadmin Ubuntu dapper *
Phpmyadmin Ubuntu edgy *
Phpmyadmin Ubuntu feisty *
Phpmyadmin Ubuntu upstream *

References