FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-5386

This CVE name corresponds to:

Entered Topic
2007-10-16 phpmyadmin -- cross-site scripting vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-5386
Phase Assigned(20071011)

Description

Cross-site scripting (XSS) vulnerability in scripts/setup.php in phpMyAdmin 2.11.1, when accessed by a browser that does not URL-encode requests, allows remote attackers to inject arbitrary web script or HTML via the query string.

References

Source Reference
BUGTRAQ 20071015 about phpMyAdmin setup.php XSS vulnerability
MISC http://www.digitrustgroup.com/advisories/TDG-advisory071009a
CONFIRM http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/branches/MAINT_2_11_1/phpMyAdmin/ChangeLog?r1=10748&r2=10747&pathrev=10748
CONFIRM http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/trunk/?view=log
CONFIRM http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-5
CONFIRM https://sourceforge.net/tracker/index.php?func=detail&aid=1810629&group_id=23067&atid=377408
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=333661
DEBIAN DSA-1403
FEDORA FEDORA-2007-2738
MANDRIVA MDKSA-2007:199
BID 26020
VUPEN ADV-2007-3469
OSVDB 37678
SECUNIA 27173
SECUNIA 27506
SECUNIA 27595
XF phpmyadmin-setup-xss(37077)