CVE-2008-2960
published 2008-07-02CVE-2008-2960: Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when register_globals is enabled and .htaccess support is disabled, allows remote…
PriorityP411low2.6CVSS 2.0
AVNACHAuNCNIPAN
EPSS
1.60%
73.2th percentile
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when register_globals is enabled and .htaccess support is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving scripts in libraries/.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | phpmyadmin | < phpmyadmin 4:2.11.7~rc2-1 (bookworm) | phpmyadmin 4:2.11.7~rc2-1 (bookworm) |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
osv2.6LOW
vendor_debian2.6LOW
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v74x-h8vc-p3j5: Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2
ghsa_unreviewed·2022-05-01
CVE-2008-2960 [LOW] CWE-79 GHSA-v74x-h8vc-p3j5: Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when register_globals is enabled and .htaccess support is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving scripts in libraries/.
OSV
CVE-2008-2960: Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2
osv·2008-07-02·CVSS 2.6
CVE-2008-2960 [LOW] CVE-2008-2960: Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when register_globals is enabled and .htaccess support is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving scripts in libraries/.
Debian
CVE-2008-2960: phpmyadmin - Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when regis...
vendor_debian·2008·CVSS 2.6
CVE-2008-2960 [LOW] CVE-2008-2960: phpmyadmin - Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when regis...
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when register_globals is enabled and .htaccess support is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving scripts in libraries/.
Scope: local
bookworm: resolved (fixed in 4:2.11.7~rc2-1)
bullseye: resolved (fixed in 4:2.11.7~rc2-1)
forky: resolved (fixed in 4:2.11.7~rc2-1)
sid: resolved (fixed in 4:2.11.7~rc2-1)
trixie: resolved (fixed in 4:2.11.7~rc2-1)
Red Hat
phpMyAdmin: XSS on plausible insecure PHP installation (PMASA-2008-4)
vendor_redhat·CVSS 2.6
CVE-2008-2960 [LOW] phpMyAdmin: XSS on plausible insecure PHP installation (PMASA-2008-4)
phpMyAdmin: XSS on plausible insecure PHP installation (PMASA-2008-4)
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when register_globals is enabled and .htaccess support is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving scripts in libraries/.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-3032 phpmyadmin XSS flaw
bugzilla·2008-07-07·CVSS 2.6
CVE-2008-3032 [LOW] CVE-2008-3032 phpmyadmin XSS flaw
CVE-2008-3032 phpmyadmin XSS flaw
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-3032 to the following vulnerability:
Cross-site scripting (XSS) vulnerability in the phpMyAdmin
(phpmyadmin) extension 3.0.1 and earlier for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
References:
Reference:
CONFIRM:http://typo3.org/teams/security/security-bulletins/typo3-20080701-2/
Reference: BID:30039
Reference: URL:http://www.securityfocus.com/bid/30039
Reference: SECUNIA:30884
Reference: URL:http://secunia.com/advisories/30884
Reference: XF:phpmyadmin-typo3-unspecified-xss(43508)
Reference: URL:http://xforce.iss.net/xforce/xfdb/43508
Discussion:
Josh, as per phpMyAdmin upstream CVE-2008-3032 is just a duplicate of the
CVE-2008-2
Bugzilla
CVE-2008-2009 vorbis: insufficient validation of Huffman tree causing memory corruption in _make_decode_tree()
bugzilla·2008-04-28·CVSS 4.3
CVE-2008-2009 [MEDIUM] CVE-2008-2009 vorbis: insufficient validation of Huffman tree causing memory corruption in _make_decode_tree()
CVE-2008-2009 vorbis: insufficient validation of Huffman tree causing memory corruption in _make_decode_tree()
Will Drewry of the Google Security Team created a set of fuzzed OGG test files
to test OGG Vorbis and Tremor implementations. Some of them were causing memory
corruption and crash on old libvorbis versions (prior to 1.0).
Crash / corruption occurred in _make_decode_tree(). This function was removed
prior to the release of upstream version 1.0 in following changes:
https://trac.xiph.org/changeset/2959
https://trac.xiph.org/changeset/2960
Test files do not crash libvobis revision 2960 or later.
Discussion:
Created attachment 303976
Patch from Monty (xiphmont)
Patch adds _check_words, a dry-run variant of _make_words, that does performs
huffman tree validation early in the str
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.htmlhttp://secunia.com/advisories/30813http://secunia.com/advisories/30816http://secunia.com/advisories/33822http://www.mandriva.com/security/advisories?name=MDVSA-2008:131http://www.openwall.com/lists/oss-security/2008/07/16/11http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-4http://www.vupen.com/english/advisories/2008/1904/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/43320http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.htmlhttp://secunia.com/advisories/30813http://secunia.com/advisories/30816http://secunia.com/advisories/33822http://www.mandriva.com/security/advisories?name=MDVSA-2008:131http://www.openwall.com/lists/oss-security/2008/07/16/11http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-4http://www.vupen.com/english/advisories/2008/1904/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/43320
2008-07-02
Published