CVE-2007-2245
published 2007-04-25CVE-2007-2245: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the…
PriorityP420medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.73%
75.1th percentile
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the fieldkey parameter to browse_foreigners.php or (2) certain input to the PMA_sanitize function.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | phpmyadmin | < phpmyadmin 4:2.10.1-1 (bookworm) | phpmyadmin 4:2.10.1-1 (bookworm) |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | >= 0 < 4:2.10.1-1 | 4:2.10.1-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:2.10.1-1 | 4:2.10.1-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:2.10.1-1 | 4:2.10.1-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:2.10.1-1 | 4:2.10.1-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2007-2245: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1....
vendor_debian·2007·CVSS 6.8
CVE-2007-2245 [MEDIUM] CVE-2007-2245: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1....
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the fieldkey parameter to browse_foreigners.php or (2) certain input to the PMA_sanitize function.
Scope: local
bookworm: resolved (fixed in 4:2.10.1-1)
bullseye: resolved (fixed in 4:2.10.1-1)
forky: resolved (fixed in 4:2.10.1-1)
sid: resolved (fixed in 4:2.10.1-1)
trixie: resolved (fixed in 4:2.10.1-1)
GHSA
GHSA-cx7j-6x8v-hjf9: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2
ghsa_unreviewed·2022-05-01
CVE-2007-2245 [MEDIUM] GHSA-cx7j-6x8v-hjf9: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the fieldkey parameter to browse_foreigners.php or (2) certain input to the PMA_sanitize function.
OSV
CVE-2007-2245: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2
osv·2007-04-25·CVSS 6.8
CVE-2007-2245 [MEDIUM] CVE-2007-2245: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the fieldkey parameter to browse_foreigners.php or (2) certain input to the PMA_sanitize function.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-4897 CVE-2007-4924 opal various flaws [F7]
bugzilla·2007-09-20·CVSS 5.0
CVE-2007-4897 [MEDIUM] CVE-2007-4897 CVE-2007-4924 opal various flaws [F7]
CVE-2007-4897 CVE-2007-4924 opal various flaws [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
Sorry, F7 version is not affected by CVE-2007-4897. Updating dependencies.
---
And I'm pushing the latest Ekiga/opal/pwlib to testing updates anyway, hopefully
this will clear everything up !
Daniel
---
Please do push to stable unless problems arose.
---
FEDORA-2007-2245. Not quite that thing though. Related at least.
Bugzilla
CVE-2007-2245: phpMyAdmin < 2.10.1 XSS vulnerabilities
bugzilla·2007-04-25·CVSS 6.8
CVE-2007-2245 [MEDIUM] CVE-2007-2245: phpMyAdmin < 2.10.1 XSS vulnerabilities
CVE-2007-2245: phpMyAdmin < 2.10.1 XSS vulnerabilities
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-2245
"Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before
2.10.1.0 allow remote attackers to inject arbitrary web script or HTML via (1)
the fieldkey parameter to browse_foreigners.php or (2) certain input to the
PMA_sanitize function."
Discussion:
As both F7 and FC6 extras have 2.11.0, I believe this should be fixed now. Mike?
---
*** Bug 356291 has been marked as a duplicate of this bug. ***
http://osvdb.org/35050http://secunia.com/advisories/24952http://secunia.com/advisories/26733http://www.mandriva.com/security/advisories?name=MDKSA-2007:199http://www.phpmyadmin.net/ChangeLog.txthttp://www.phpmyadmin.net/home_page/downloads.php?relnotes=0http://www.us.debian.org/security/2007/dsa-1370http://www.vupen.com/english/advisories/2007/1508https://exchange.xforce.ibmcloud.com/vulnerabilities/33898http://osvdb.org/35050http://secunia.com/advisories/24952http://secunia.com/advisories/26733http://www.mandriva.com/security/advisories?name=MDKSA-2007:199http://www.phpmyadmin.net/ChangeLog.txthttp://www.phpmyadmin.net/home_page/downloads.php?relnotes=0http://www.us.debian.org/security/2007/dsa-1370http://www.vupen.com/english/advisories/2007/1508https://exchange.xforce.ibmcloud.com/vulnerabilities/33898
2007-04-25
Published