Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.100068
Category:Web application abuses
Title:phpMyAdmin Multiple Input Validation Vulnerabilities
Summary:phpMyAdmin is prone to multiple input-validation vulnerabilities,; including an HTML-injection vulnerability, cross-site scripting vulnerabilities, and information-disclosure; vulnerabilities.
Description:Summary:
phpMyAdmin is prone to multiple input-validation vulnerabilities,
including an HTML-injection vulnerability, cross-site scripting vulnerabilities, and information-disclosure
vulnerabilities.

Vulnerability Impact:
An attacker could exploit these vulnerabilities to view sensitive
information or to have arbitrary script code execute in the context of the affected site, which may
allow the attacker to steal cookie-based authentication credentials or change the way the site
is rendered to the user. Data gained could aid in further attacks.

Solution:
Update to version 2.9.1.1 or later.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2006-6942
BugTraq ID: 21137
http://www.securityfocus.com/bid/21137
Bugtraq: 20061116 PhpMyAdmin all version [multiples vulnerability] (Google Search)
http://marc.info/?l=bugtraq&m=116370414309444&w=2
Debian Security Information: DSA-1370 (Google Search)
http://www.us.debian.org/security/2007/dsa-1370
http://secunia.com/advisories/26733
http://www.vupen.com/english/advisories/2006/4572
XForce ISS Database: phpmyadmin-multiple-parameter-xss(30310)
https://exchange.xforce.ibmcloud.com/vulnerabilities/30310
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.