CVE-2011-3598
phppgadmin < 5.0.3 - Cross-Site Scripting via Web Page Title or return_url/return_desc Parameters
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in phpPgAdmin before 5.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) a web page title, related to classes/Misc.php; or the (2) return_url or (3) return_desc parameter to display.php.
References (16)
Core 16
Core References
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-October/067843.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/46426
Patch mailing-list
x_refsource_mlist
http://sourceforge.net/mailarchive/forum.php?thread_name=4E897F6C.90905%40free.fr&forum_name=phppgadmin-news
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2012-04/msg00033.html
Patch x_refsource_confirm
https://github.com/phppgadmin/phppgadmin/commit/1df248203de055f97e092b50b1dd9643ccb73842
Issue Tracking x_refsource_confirm
https://bugs.gentoo.org/show_bug.cgi?id=385505
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/46248
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/75998
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-October/067846.html
Patch mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/10/04/10
Release Notes x_refsource_confirm
http://freshmeat.net/projects/phppgadmin/releases/336969
Patch mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/10/04/1
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/49914
Patch x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=743205
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/75997
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-October/068009.html
Scores
EPSS
0.0253
EPSS Percentile
83.2%
Details
CWE
CWE-79
Status
published
Products (17)
phppgadmin/phppgadmin
2.2
phppgadmin/phppgadmin
2.2.1
phppgadmin/phppgadmin
3.1
phppgadmin/phppgadmin
3.2
phppgadmin/phppgadmin
3.3
phppgadmin/phppgadmin
3.4
phppgadmin/phppgadmin
3.4.1
phppgadmin/phppgadmin
3.5
phppgadmin/phppgadmin
3.5.2
phppgadmin/phppgadmin
3.5.3
... and 7 more
Published
Oct 08, 2011
Tracked Since
Feb 18, 2026