CVE-2012-1600Cross-site Scripting in Phppgadmin

Severity
4.3MEDIUMNVD
EPSS
0.6%
top 31.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 14
Latest updateMay 14

Description

Multiple cross-site scripting (XSS) vulnerabilities in functions.php in phpPgAdmin before 5.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) type of a function.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages4 packages

debiandebian/phppgadmin< phppgadmin 5.0.4-1 (forky)
Debianphppgadmin_project/phppgadmin< 5.0.4-1+1
NVDopensuse/opensuse11.4, 12.1+1

🔴Vulnerability Details

2
GHSA
GHSA-36cx-v49w-m2cw: Multiple cross-site scripting (XSS) vulnerabilities in functions2022-05-14
OSV
CVE-2012-1600: Multiple cross-site scripting (XSS) vulnerabilities in functions2014-05-14

📋Vendor Advisories

1
Debian
CVE-2012-1600: phppgadmin - Multiple cross-site scripting (XSS) vulnerabilities in functions.php in phpPgAdm...2012

💬Community

1
Bugzilla
CVE-2012-1600 phpPgAdmin: XSS by displaying default list of functions in the database2012-03-30