CVE-2007-5977

Publication date 15 November 2007

Last updated 24 July 2024


Ubuntu priority

Cross-site scripting (XSS) vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to inject arbitrary web script or HTML via a hex-encoded IMG element in the db parameter in a POST request, a different vulnerability than CVE-2006-6942.

Read the notes from the security team

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
phpmyadmin 7.10 gutsy
Fixed 4:2.10.3-1ubuntu0.1
7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected

Notes


fujitsu

PMASA-2007-7 Dapper/Edgy/Feisty have a non-vulnerable version of the code.