[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-5728Date: (C)2007-10-30   (M)2023-12-22


Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, allows remote attackers to inject arbitrary web script or HTML via certain input available in PHP_SELF in (1) redirect.php, possibly related to (2) login.php, different vectors than CVE-2007-2865.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
http://lists.grok.org.uk/pipermail/full-disclosure/2007-May/063617.html
BID-24182
SECUNIA-25446
SECUNIA-27756
SECUNIA-33263
OSVDB-36699
DSA-1693
SUSE-SR:2007:024
phppgadmin-redirect-xss(34550)

CWE    1
CWE-79
OVAL    1
oval:org.mitre.oval:def:7719

© SecPod Technologies