6.8

CVE-2004-1055

Exploit

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PmaAbsoluteUri parameter, (2) the zero_rows parameter in read_dump.php, (3) the confirm form, or (4) an error message generated by the internal phpMyAdmin parser.

Data is provided by the National Vulnerability Database (NVD)
PhpmyadminPhpmyadmin Version2.5.0
PhpmyadminPhpmyadmin Version2.5.1
PhpmyadminPhpmyadmin Version2.5.2
PhpmyadminPhpmyadmin Version2.5.4
PhpmyadminPhpmyadmin Version2.5.5
PhpmyadminPhpmyadmin Version2.5.5_pl1
PhpmyadminPhpmyadmin Version2.5.5_rc1
PhpmyadminPhpmyadmin Version2.5.5_rc2
PhpmyadminPhpmyadmin Version2.5.6_rc1
PhpmyadminPhpmyadmin Version2.5.7
PhpmyadminPhpmyadmin Version2.5.7_pl1
PhpmyadminPhpmyadmin Version2.6.0_pl1
PhpmyadminPhpmyadmin Version2.6.0_pl2
GentooLinux Version1.4
GentooLinux Version1.4 Updaterc1
GentooLinux Version1.4 Updaterc2
GentooLinux Version1.4 Updaterc3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.17% 0.767
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P