PT-2005-1596 · Php · Phpmyadmin

Maksymilian Arciemowicz

·

Published

2005-02-24

·

Updated

2017-07-11

·

CVE-2005-0543

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions phpMyAdmin version 2.6.1
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary HTML and web script. This can be achieved via the strServer, cfg[BgcolorOne], or strServerChoice parameters in select server.lib.php, the bg color or row no parameters in display tbl links.lib.php, the left font family parameter in theme left.css.php, or the right font family parameter in theme right.css.php.
Recommendations For phpMyAdmin version 2.6.1, as a temporary workaround, consider restricting access to the vulnerable parameters strServer, cfg[BgcolorOne], strServerChoice, bg color, row no, left font family, and right font family until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2005-0543

Affected Products

Phpmyadmin