FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-5589

This CVE name corresponds to:

Entered Topic
2007-10-17 phpmyadmin -- cross-site scripting vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-5589
Phase Assigned(20071019)

Description

Muliple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.11.1.2 allow remote attackers to inject arbitrary web script or HTML via certain input available in (1) PHP_SELF in (a) server_status.php, and (b) grab_globals.lib.php, (c) display_change_password.lib.php, and (d) common.lib.php in libraries/; and certain input available in PHP_SELF and (2) PATH_INFO in libraries/common.inc.php. NOTE: there might also be other vectors related to (3) REQUEST_URI.

References

Source Reference
MISC http://www.digitrustgroup.com/advisories/TDG-advisory071015a.html
CONFIRM http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/branches/MAINT_2_11_1/phpMyAdmin/ChangeLog?r1=10796&r2=10795&pathrev=10796
CONFIRM http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin?view=rev&revision=10796
CONFIRM http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-6
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=333661
DEBIAN DSA-1403
FEDORA FEDORA-2007-2738
MANDRIVA MDKSA-2007:199
SUSE SUSE-SR:2008:006
BID 26301
VUPEN ADV-2007-3535
OSVDB 37939
SECUNIA 27246
SECUNIA 27506
SECUNIA 27595
SECUNIA 29323
XF phpmyadmin-serverstatus-xss(37292)