CVE-2005-0543
phpMyAdmin 2.6.1 - Cross-Site Scripting via Multiple Parameters
Title source: llmExploitation Summary
EIP tracks 4 public exploits for CVE-2005-0543. PoCs published by Maksymilian Arciemowicz.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in phpMyAdmin due to insufficient input sanitization. It includes a sample URL demonstrating the vulnerability but lacks executable exploit code.
Description
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerChoice parameters in select_server.lib.php, (2) the bg_color or row_no parameters in display_tbl_links.lib.php, the left_font_family parameter in theme_left.css.php, or the right_font_family parameter in theme_right.css.php.
Exploits (4)
The provided text describes a cross-site scripting (XSS) vulnerability in phpMyAdmin due to insufficient input sanitization. It includes a sample URL demonstrating the vulnerability but lacks executable exploit code.
The provided text describes a cross-site scripting (XSS) vulnerability in phpMyAdmin due to insufficient input sanitization. It includes a sample URL demonstrating the vulnerability but lacks executable exploit code.
This exploit demonstrates multiple XSS vulnerabilities in phpMyAdmin due to insufficient input sanitization. The PoC provides URLs with crafted parameters that inject arbitrary script code into dynamically generated web content.
This exploit demonstrates multiple XSS vulnerabilities in phpMyAdmin due to insufficient input sanitization. The PoC provides URLs with injected script code that executes in the context of a user's browser session.