CVE-2007-5728
NUCLEIphppgadmin 3.5-4.1.1 - Cross-Site Scripting via PHP_SELF in redirect.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5728. PoCs published by Michal Majchrowicz. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in phpPgAdmin via the redirect.php script. The PoC uses a crafted URL to inject and execute arbitrary JavaScript code in the context of the affected website.
Description
Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, allows remote attackers to inject arbitrary web script or HTML via certain input available in PHP_SELF in (1) redirect.php, possibly related to (2) login.php, different vectors than CVE-2007-2865.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in phpPgAdmin via the redirect.php script. The PoC uses a crafted URL to inject and execute arbitrary JavaScript code in the context of the affected website.
Nuclei Templates (1)
http.title:"phpPgAdmin" || http.title:phppgadmin || cpe:"cpe:2.3:a:phppgadmin_project:phppgadmin"
title=phppgadmin