CVE-2008-4775

Publication date 28 October 2008

Last updated 24 July 2024


Ubuntu priority

Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
phpmyadmin 9.04 jaunty
Not affected
8.10 intrepid
Fixed 4:2.11.8.1-1ubuntu0.1
8.04 LTS hardy
Fixed 4:2.11.3-1ubuntu1.2
7.10 gutsy Ignored end of life, was needed
6.06 LTS dapper
Not affected

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
phpmyadmin