Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2007-1395

Опубликовано: 10 мар. 2007
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3

Описание

Incomplete blacklist vulnerability in index.php in phpMyAdmin 2.8.0 through 2.9.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by injecting arbitrary JavaScript or HTML in a (1) db or (2) table parameter value followed by an uppercase end tag, which bypasses the protection against lowercase .

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

edgy

ignored

end of life, was needed
feisty

released

4:2.9.1.1-2ubuntu1.1
gutsy

not-affected

hardy

not-affected

intrepid

not-affected

jaunty

not-affected

karmic

not-affected

upstream

released

2.10.0.2

Показывать по

Ссылки на источники

4.3 Medium

CVSS2

Связанные уязвимости

nvd
почти 19 лет назад

Incomplete blacklist vulnerability in index.php in phpMyAdmin 2.8.0 through 2.9.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by injecting arbitrary JavaScript or HTML in a (1) db or (2) table parameter value followed by an uppercase </SCRIPT> end tag, which bypasses the protection against lowercase </script>.

debian
почти 19 лет назад

Incomplete blacklist vulnerability in index.php in phpMyAdmin 2.8.0 th ...

github
почти 4 года назад

Incomplete blacklist vulnerability in index.php in phpMyAdmin 2.8.0 through 2.9.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by injecting arbitrary JavaScript or HTML in a (1) db or (2) table parameter value followed by an uppercase </SCRIPT> end tag, which bypasses the protection against lowercase </script>.

4.3 Medium

CVSS2