FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

phpmyadmin -- Cross Site Scripting

Affected packages
phpmyadmin < 2.11.2.2

Details

VuXML ID 15485ae8-9848-11dc-9e48-0016179b2dd5
Discovery 2007-11-20
Entry 2007-11-21
Modified 2010-05-12

phpMyAdmin security announcement:

The login page auth_type cookie was vulnerable to XSS via the convcharset parameter. An attacker could use this to execute malicious code on the visitors computer

References

CVE Name CVE-2007-6100
URL http://www.nth-dimension.org.uk/downloads.php?id=38
URL http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-8