Description
Cross-site scripting (XSS) vulnerability in mysql/phpinfo.php in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the lang[] parameter.
CVSS vector
AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9Confidentiality: None
Availability: None
Affected Packages3 packages
🔴Vulnerability Details
3GHSAGHSA-cj7j-6rg9-9523: Cross-site scripting (XSS) vulnerability in mysql/phpinfo↗2022-05-01 ▶ Kernelnamei: allow restricted O_CREAT of FIFOs and regular files↗2018-08-23 ▶ OSVCVE-2007-2016: Cross-site scripting (XSS) vulnerability in mysql/phpinfo↗2007-04-12 ▶ 💥Exploits & PoCs
4Exploit-DBMicrosoft Excel - OLE Arbitrary Code Execution↗2017-09-30 ▶ Exploit-DBMicrosoft Word 2007/2010/2013/2016 - Out-of-Bounds Read Code Execution (MS16-099)↗2016-08-10 ▶ Exploit-DBMicrosoft Excel - Out-of-Bounds Read Code Execution (MS16-042)↗2016-04-14 ▶ Exploit-DBSkilMatch Systems JobLister3 - 'index.php' SQL Injection↗2007-07-13 ▶ 📋Vendor Advisories
2Red Hatkernel: v4l: videobuf: hotfix a bug on multiple calls to mmap()↗2010-07-29 ▶ DebianCVE-2007-2016: phpmyadmin - Cross-site scripting (XSS) vulnerability in mysql/phpinfo.php in phpMyAdmin 2.6....↗2007 ▶ 💬Community
2BugzillaCVE-2016-5177 chromium-browser: use after free in v8↗2016-09-30 ▶ BugzillaCVE-2016-5178 chromium-browser: various fixes from internal audits↗2016-09-30 ▶