Executive Summary

Informations
Name CVE-2007-4306 First vendor Publication 2007-08-13
Vendor Cve Last vendor Modification 2008-09-05

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Cvss Base Score 4.3 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.10.3 allow remote attackers to inject arbitrary web script or HTML via the (1) unlim_num_rows, (2) sql_query, or (3) pos parameter to (a) tbl_export.php; the (4) session_max_rows or (5) pos parameter to (b) sql.php; the (6) username parameter to (c) server_privileges.php; or the (7) sql_query parameter to (d) main.php. NOTE: vector 5 might be a regression or incomplete fix for CVE-2006-6942.7.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4306

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1

Open Source Vulnerability Database (OSVDB)

Id Description
38720 phpMyAdmin Multiple Parameter XSS

phpMyAdmin contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'unlim_num_rows', 'sql_query' and 'pos_parameter' variables upon submission to the tbl_export.php script, 'session_max_rows' and 'pos_parameter' variables upon submission to the sql.php script, 'username' variable upon submission to the server_privileges.php script and 'sql_query' variable upon submission to the main.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/25268
MANDRIVA http://www.mandriva.com/security/advisories?name=MDKSA-2007:199
MISC http://pridels-team.blogspot.com/2007/08/phpmyadmin-multiple-xss-vuln.html

Alert History

If you want to see full details history, please login or register.
0
1
2
3
Date Informations
2021-05-04 12:06:15
  • Multiple Updates
2021-04-22 01:06:47
  • Multiple Updates
2020-05-23 00:20:16
  • Multiple Updates
2013-05-11 10:33:49
  • Multiple Updates