CVE-2007-6100

phpMyAdmin <2.11.2.2 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in libraries/auth/cookie.auth.lib.php in phpMyAdmin before 2.11.2.2, when logins are authenticated with the cookie auth_type, allows remote attackers to inject arbitrary web script or HTML via the convcharset parameter to index.php, a different vulnerability than CVE-2005-0992.

Scores

EPSS 0.0054
EPSS Percentile 67.2%

Classification

CWE
CWE-79
Status draft

Affected Products (50)

phpmyadmin/phpmyadmin < 2.11.2.1
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
... and 35 more

Timeline

Published Nov 23, 2007
Tracked Since Feb 18, 2026