CVE-2005-3301
phpMyAdmin - Cross-Site Scripting via left.php, queryframe.php, or server_databases.php
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2005-3301. PoCs published by Tobias Klein.
AI-analyzed exploit summary This exploit demonstrates multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin due to improper input sanitization. The PoC includes URLs with injected JavaScript to steal cookies.
Description
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) left.php, (2) queryframe.php, or (3) server_databases.php.
Exploits (2)
This exploit demonstrates multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin due to improper input sanitization. The PoC includes URLs with injected JavaScript to steal cookies.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in phpMyAdmin by injecting a malicious script via the 'hash' parameter in the queryframe.php URL. The PoC uses a simple alert to display the user's cookies, proving the vulnerability.