Executive Summary

Informations
Name CVE-2007-2245 First vendor Publication 2007-04-25
Vendor Cve Last vendor Modification 2017-07-29

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Cvss Base Score 6.8 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the fieldkey parameter to browse_foreigners.php or (2) certain input to the PMA_sanitize function.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2245

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:18380
 
Oval ID: oval:org.mitre.oval:def:18380
Title: DSA-1370-2 phpmyadmin - several vulnerabilities
Description: Several remote vulnerabilities have been discovered in phpMyAdmin, a program to administrate MySQL over the web.
Family: unix Class: patch
Reference(s): DSA-1370-2
CVE-2006-6942
CVE-2006-6944
CVE-2007-1325
CVE-2007-1395
CVE-2007-2245
Version: 5
Platform(s): Debian GNU/Linux 4.0
Product(s): phpmyadmin
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:20451
 
Oval ID: oval:org.mitre.oval:def:20451
Title: DSA-1370-1 phpmyadmin - several vulnerabilities
Description: Several remote vulnerabilities have been discovered in phpMyAdmin, a program to administrate MySQL over the web.
Family: unix Class: patch
Reference(s): DSA-1370-1
CVE-2006-6942
CVE-2006-6944
CVE-2007-1325
CVE-2007-1395
CVE-2007-2245
Version: 5
Platform(s): Debian GNU/Linux 4.0
Product(s): phpmyadmin
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1

OpenVAS Exploits

Date Description
2008-01-17 Name : Debian Security Advisory DSA 1370-1 (phpmyadmin)
File : nvt/deb_1370_1.nasl
2008-01-17 Name : Debian Security Advisory DSA 1370-2 (phpmyadmin)
File : nvt/deb_1370_2.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
35050 phpMyAdmin browse_foreigners.php fieldkey Parameter XSS

Nessus® Vulnerability Scanner

Date Description
2007-09-14 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-1370.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

Source Url
CONFIRM http://www.phpmyadmin.net/ChangeLog.txt
http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0
DEBIAN http://www.us.debian.org/security/2007/dsa-1370
MANDRIVA http://www.mandriva.com/security/advisories?name=MDKSA-2007:199
OSVDB http://osvdb.org/35050
SECUNIA http://secunia.com/advisories/24952
http://secunia.com/advisories/26733
VUPEN http://www.vupen.com/english/advisories/2007/1508
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/33898

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
Date Informations
2021-05-04 12:05:41
  • Multiple Updates
2021-04-22 01:06:15
  • Multiple Updates
2020-05-23 00:19:38
  • Multiple Updates
2017-07-29 12:02:11
  • Multiple Updates
2016-06-28 16:24:22
  • Multiple Updates
2016-04-26 16:02:34
  • Multiple Updates
2014-02-17 10:39:57
  • Multiple Updates
2013-05-11 10:23:55
  • Multiple Updates