CVE-2008-4326

Phpmyadmin < 2.11.9.1 - XSS

Title source: rule

Description

The PMA_escapeJsString function in libraries/js_escape.lib.php in phpMyAdmin before 2.11.9.2, when Internet Explorer is used, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via a NUL byte inside a "</script" sequence.

Scores

EPSS 0.0043
EPSS Percentile 61.9%

Classification

CWE
CWE-79
Status published

Affected Products (50)

phpmyadmin/phpmyadmin < 2.11.9.1
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
... and 35 more

Timeline

Published Sep 30, 2008
Tracked Since Feb 18, 2026