CVE-2007-0204Cross-site Scripting in Phpmyadmin

4 documents4 sources
Severity
6.8MEDIUMNVD
EPSS
1.6%
top 18.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 11
Latest updateMay 1

Description

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.9.2-rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages3 packages

debiandebian/phpmyadmin< phpmyadmin 4:2.9.1.1-2 (bookworm)
Debianphpmyadmin/phpmyadmin< 4:2.9.1.1-2+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-j43g-fq6v-2f6j: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 22022-05-01
OSV
CVE-2007-0204: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 22007-01-11

📋Vendor Advisories

1
Debian
CVE-2007-0204: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.9.2-r...2007