CVE-2010-3056Cross-site Scripting in Phpmyadmin

CWE-79Cross-site Scripting11 documents6 sources
Severity
4.3MEDIUMNVD
EPSS
0.8%
top 26.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 24
Latest updateMay 17

Description

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.11.x before 2.11.10.1 and 3.x before 3.3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) db_search.php, (2) db_sql.php, (3) db_structure.php, (4) js/messages.php, (5) libraries/common.lib.php, (6) libraries/database_interface.lib.php, (7) libraries/dbi/mysql.dbi.lib.php, (8) libraries/dbi/mysqli.dbi.lib.php, (9) libraries/db_info.inc.php, (10) libraries/sanitizing.lib.php, (11) librar

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages4 packages

debiandebian/phpmyadmin< phpmyadmin 4:3.3.5.1-1 (bookworm)+1
Packagistphpmyadmin/phpmyadmin3.0.03.3.6
Debianphpmyadmin/phpmyadmin< 4:3.3.5.1-1+7
NVDphpmyadmin/phpmyadmin45 versions+44

Patches

🔴Vulnerability Details

5
GHSA
phpMyAdmin Cross-site Scripting vulnerability2022-05-17
GHSA
GHSA-vwc7-2mqc-8723: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 22022-05-17
OSV
phpMyAdmin Cross-site Scripting vulnerability2022-05-17
OSV
CVE-2010-2958: Cross-site scripting (XSS) vulnerability in libraries/Error2010-09-08
OSV
CVE-2010-3056: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 22010-08-24

📋Vendor Advisories

2
Debian
CVE-2010-3056: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.11.x before ...2010
Debian
CVE-2010-2958: phpmyadmin - Cross-site scripting (XSS) vulnerability in libraries/Error.class.php in phpMyAd...2010

💬Community

2
Bugzilla
CVE-2010-3056 phpMyAdmin: several XSS vulnerabilities fixed in 3.3.5.1/2.11.10.12010-08-20
Bugzilla
CVE-2010-3056 phpMyAdmin: several XSS vulnerabilities fixed in 3.3.5.1/2.11.10.1 [fedora-all]2010-08-20