Vulnerability Details CVE-2008-2960
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when register_globals is enabled and .htaccess support is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving scripts in libraries/.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 69.6%
CVSS Severity
CVSS v2 Score 2.6
Products affected by CVE-2008-2960
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.10.0
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.10.0.1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.10.0.2
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.10.1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.10.2
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.10.3
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.10.3rc1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.0
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.0beta1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.0rc1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.1.1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.1.2
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.1rc1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.2
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.2.1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.2.2
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.3
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.3rc1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.4
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.4rc1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.5
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.5.1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.5.2
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.5rc1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.6
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.6rc1