CVE-2005-3665: XSS
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.7.0 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTPHOST variable and (2) various scripts in the libraries directory that handle header generation.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3665?
CVE-2005-3665 is classified as a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
How do I fix CVE-2005-3665?
To fix CVE-2005-3665, update phpMyAdmin to version 2.7.0 or later, which resolves the identified vulnerabilities.
What types of vulnerabilities does CVE-2005-3665 exploit?
CVE-2005-3665 exploits multiple cross-site scripting (XSS) vulnerabilities that allow remote attackers to inject arbitrary web scripts or HTML.
Which versions of phpMyAdmin are affected by CVE-2005-3665?
CVE-2005-3665 affects various versions of phpMyAdmin prior to 2.7.0, including versions 2.0, 2.1, 2.2, and 2.6.
Can I mitigate CVE-2005-3665 without updating software?
Mitigation without updating is not recommended as it requires code changes to filter untrusted input adequately, making upgrading highly advisable.