Incomplete blacklist vulnerability in index.php in phpMyAdmin 2.8.0 through 2.9.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by injecting arbitrary JavaScript or HTML in a (1) db or (2) table parameter value followed by an uppercase </SCRIPT> end tag, which bypasses the protection against lowercase </script>.
2007-03-10T22:19:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | phpmyadmin | phpmyadmin | 2.8.0 | Yes |
Application | phpmyadmin | phpmyadmin | 2.8.0.1 | Yes |
Application | phpmyadmin | phpmyadmin | 2.8.0.2 | Yes |
Application | phpmyadmin | phpmyadmin | 2.8.0.3 | Yes |
Application | phpmyadmin | phpmyadmin | 2.8.1 | Yes |
Application | phpmyadmin | phpmyadmin | 2.8.1_dev | Yes |
Application | phpmyadmin | phpmyadmin | 2.8.2 | Yes |
Application | phpmyadmin | phpmyadmin | 2.8.3 | Yes |
Application | phpmyadmin | phpmyadmin | 2.8.4 | Yes |
Application | phpmyadmin | phpmyadmin | 2.9 | Yes |
Application | phpmyadmin | phpmyadmin | 2.9.0 | Yes |
Application | phpmyadmin | phpmyadmin | 2.9.0.1 | Yes |
Application | phpmyadmin | phpmyadmin | 2.9.0.2 | Yes |
Application | phpmyadmin | phpmyadmin | 2.9.0.3 | Yes |
Application | phpmyadmin | phpmyadmin | 2.9.0_beta1 | Yes |
Application | phpmyadmin | phpmyadmin | 2.9.0_dev | Yes |
Application | phpmyadmin | phpmyadmin | 2.9.0_rc1 | Yes |
Application | phpmyadmin | phpmyadmin | 2.9.1 | Yes |
Application | phpmyadmin | phpmyadmin | 2.9.1.1 | Yes |
Application | phpmyadmin | phpmyadmin | 2.9.1_rc1 | Yes |
Application | phpmyadmin | phpmyadmin | 2.9.1_rc2 | Yes |
Application | phpmyadmin | phpmyadmin | 2.9.2 | Yes |