CVE-2008-4775
phpMyAdmin 3.0.1 - 'pmd_pdf.php' Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en pmd_pdf.php en phpMyAdmin v3.0.0, y posiblemente otras versiones incluyendo v2.11.9.2 y v3.0.1, cuando register_globals está activo, permite a atacantes remotos inyectar web script o HTML a través del parámetro "db", un vector diferente a CVE-2006-6942 y CVE-2007-5977.
phpMyAdmin suffered from cross site scripting, cross site request forgery, and SQL injection vulnerabilities. This update provide the fix for these security issues. The previous update packages wasn't signed, this time they are.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-10-28 CVE Reserved
- 2008-10-28 CVE Published
- 2014-03-26 First Exploit
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/4516 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/497815/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/31928 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/2943 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/46136 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/32531 | 2014-03-26 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/32449 | 2018-10-11 | |
http://secunia.com/advisories/32482 | 2018-10-11 | |
http://security.gentoo.org/glsa/glsa-200903-32.xml | 2018-10-11 | |
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00908.html | 2018-10-11 | |
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00925.html | 2018-10-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 2.11.9.2 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "2.11.9.2" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 3.0.0 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "3.0.0" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 3.0.1 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "3.0.1" | - |
Affected
|