Description
Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin 2.8.0.3, 2.8.0.2, 2.8.1-dev, and 2.9.0-dev allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
CVSS vector
AV:N/AC:H/C:N/I:P/A:NExploitability: 4.9 | Impact: 2.9Complexity: High
Confidentiality: None
Availability: None
Affected Packages3 packages
🔴Vulnerability Details
4GHSAGHSA-r43p-59cr-4g96: Cross-site scripting (XSS) vulnerability in index↗2022-05-01 ▶ GHSAGHSA-x5rx-xjw2-pgfp: Cross-site scripting (XSS) vulnerability in phpMyAdmin 2↗2022-05-01 ▶ OSVCVE-2006-2417: Cross-site scripting (XSS) vulnerability in phpMyAdmin 2↗2006-05-16 ▶ OSVCVE-2006-2031: Cross-site scripting (XSS) vulnerability in index↗2006-04-26 ▶ 📋Vendor Advisories
2DebianCVE-2006-2031: phpmyadmin - Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin 2.8.0.3, 2.8...↗2006 ▶ DebianCVE-2006-2417: phpmyadmin - Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.x before 2.8.0.4 al...↗2006 ▶