>> phpMyAdmin Multiple Scripts Cross Site Scripting Vulnerabilities
Title : phpMyAdmin Multiple Scripts Cross Site Scripting Vulnerabilities VUPEN ID : VUPEN/ADV-2005-2772 CVE ID : CVE-2005-3665
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-12-06
Technical Description
Multiple vulnerabilities were identified in phpMyAdmin, which may be exploited by attackers to inject malicious HTML code. These flaws are due to errors when processing input passed to the "HTTP_HOST" variable and certain scripts in the "libraries" directory, which may be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.