Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2005-2869Cross-site Scripting in Phpmyadmin

5 documents5 sources
Severity
4.3MEDIUMNVD
EPSS
11.8%
top 6.26%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedSep 8
Latest updateMay 1

Description

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/phpmyadmin< phpmyadmin 4:2.6.4-pl1-1 (bookworm)
Debianphpmyadmin/phpmyadmin< 4:2.6.4-pl1-1+3
NVDphpmyadmin/phpmyadmin46 versions+45

🔴Vulnerability Details

2
GHSA
GHSA-f47h-66wf-9744: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 22022-05-01
OSV
CVE-2005-2869: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 22005-09-08

💥Exploits & PoCs

1
Exploit-DB
phpMyAdmin 2.x - 'error.php' Cross-Site Scripting2005-08-28

📋Vendor Advisories

1
Debian
CVE-2005-2869: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 a...2005