Advertisement






phpMyAdmin XSS and SQL Injection Vulnerabilities

CVE Category Price Severity
N/A CWE-79, CWE-89 Not specified High
Author Risk Exploitation Type Date
Not specified High Remote 2009-10-26
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2009100125

Below is a copy:

Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted MySQL table name.
SQL injection vulnerability allows remote attackers to inject SQL via various interface parameters of the PDF schema generator feature.

References:
-----------
http://www.phpmyadmin.net/home_page/security/PMASA-2009-6.php
http://www.phpmyadmin.net/home_page/news.php
https://bugzilla.redhat.com/show_bug.cgi?id=528769
http://bugs.gentoo.org/show_bug.cgi?id=288899
http://www.mandriva.com/en/security/advisories?name=MDVSA-2009:274

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum