Php · Phpmyadmin · CVE-2007-1395
**Name of the Vulnerable Software and Affected Versions**
phpMyAdmin versions 2.8.0 through 2.9.2
**Description**
The issue allows remote attackers to conduct cross-site scripting (XSS) attacks by injecting arbitrary JavaScript or HTML in a `db` or `table` parameter value followed by an uppercase </SCRIPT> end tag, which bypasses the protection against lowercase </script>.
**Recommendations**
For phpMyAdmin versions 2.8.0 through 2.9.2, consider updating to a version that includes a fix for this issue, as no specific workaround is provided for these versions.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.