Vulnerabilities > CVE-2007-2245 - Unspecified vulnerability in PHPmyadmin 2.10.1.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN phpmyadmin
nessus
Summary
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the fieldkey parameter to browse_foreigners.php or (2) certain input to the PMA_sanitize function.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-1370.NASL |
description | Several remote vulnerabilities have been discovered in phpMyAdmin, a program to administrate MySQL over the web. The Common Vulnerabilities and Exposures project identifies the following problems : - CVE-2007-1325 The PMA_ArrayWalkRecursive function in libraries/common.lib.php does not limit recursion on arrays provided by users, which allows context-dependent attackers to cause a denial of service (web server crash) via an array with many dimensions. This issue affects only the stable distribution (Etch). - CVE-2007-1395 Incomplete blacklist vulnerability in index.php allows remote attackers to conduct cross-site scripting (XSS) attacks by injecting arbitrary JavaScript or HTML in a (1) db or (2) table parameter value followed by an uppercase </SCRIPT> end tag, which bypasses the protection against lowercase </script>. This issue affects only the stable distribution (Etch). - CVE-2007-2245 Multiple cross-site scripting (XSS) vulnerabilities allow remote attackers to inject arbitrary web script or HTML via (1) the fieldkey parameter to browse_foreigners.php or (2) certain input to the PMA_sanitize function. - CVE-2006-6942 Multiple cross-site scripting (XSS) vulnerabilities allow remote attackers to inject arbitrary HTML or web script via (1) a comment for a table name, as exploited through (a) db_operations.php, (2) the db parameter to (b) db_create.php, (3) the newname parameter to db_operations.php, the (4) query_history_latest, (5) query_history_latest_db, and (6) querydisplay_tab parameters to (c) querywindow.php, and (7) the pos parameter to (d) sql.php. This issue affects only the oldstable distribution (Sarge). - CVE-2006-6944 phpMyAdmin allows remote attackers to bypass Allow/Deny access rules that use IP addresses via false headers. This issue affects only the oldstable distribution (Sarge). |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 26031 |
published | 2007-09-14 |
reporter | This script is Copyright (C) 2007-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/26031 |
title | Debian DSA-1370-1 : phpmyadmin - several vulnerabilities |
code |
|
References
- http://osvdb.org/35050
- http://osvdb.org/35050
- http://secunia.com/advisories/24952
- http://secunia.com/advisories/24952
- http://secunia.com/advisories/26733
- http://secunia.com/advisories/26733
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:199
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:199
- http://www.phpmyadmin.net/ChangeLog.txt
- http://www.phpmyadmin.net/ChangeLog.txt
- http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0
- http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0
- http://www.us.debian.org/security/2007/dsa-1370
- http://www.us.debian.org/security/2007/dsa-1370
- http://www.vupen.com/english/advisories/2007/1508
- http://www.vupen.com/english/advisories/2007/1508
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33898
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33898