First published: Wed Nov 23 2005(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.7.0 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP_HOST variable and (2) various scripts in the libraries directory that handle header generation.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyAdmin phpMyAdmin | =2.1.1 | |
phpMyAdmin phpMyAdmin | =2.6.4_rc1 | |
phpMyAdmin phpMyAdmin | =2.2.4 | |
phpMyAdmin phpMyAdmin | =2.1.2 | |
phpMyAdmin phpMyAdmin | =2.2_pre1 | |
phpMyAdmin phpMyAdmin | =2.5.0 | |
phpMyAdmin phpMyAdmin | =2.2 | |
phpMyAdmin phpMyAdmin | =2.6.4_pl1 | |
phpMyAdmin phpMyAdmin | =2.0.4 | |
phpMyAdmin phpMyAdmin | =2.6.1 | |
phpMyAdmin phpMyAdmin | =2.6.1_pl3 | |
phpMyAdmin phpMyAdmin | =2.3.1 | |
phpMyAdmin phpMyAdmin | =2.0.2 | |
phpMyAdmin phpMyAdmin | =2.5.5_rc1 | |
phpMyAdmin phpMyAdmin | =2.6.0_pl3 | |
phpMyAdmin phpMyAdmin | =2.5.7_pl1 | |
phpMyAdmin phpMyAdmin | =2.4.0 | |
phpMyAdmin phpMyAdmin | =2.5.5 | |
phpMyAdmin phpMyAdmin | =2.5.7 | |
phpMyAdmin phpMyAdmin | =2.6.2_rc1 | |
phpMyAdmin phpMyAdmin | =2.5.6_rc1 | |
phpMyAdmin phpMyAdmin | =2.0.3 | |
phpMyAdmin phpMyAdmin | =2.6.1_pl1 | |
phpMyAdmin phpMyAdmin | =2.2.6 | |
phpMyAdmin phpMyAdmin | =2.6.0_pl1 | |
phpMyAdmin phpMyAdmin | =2.6.4_pl3 | |
phpMyAdmin phpMyAdmin | =2.5.2 | |
phpMyAdmin phpMyAdmin | =2.1 | |
phpMyAdmin phpMyAdmin | =2.0.1 | |
phpMyAdmin phpMyAdmin | =2.6.2 | |
phpMyAdmin phpMyAdmin | =2.5.1 | |
phpMyAdmin phpMyAdmin | =2.6.0_pl2 | |
phpMyAdmin phpMyAdmin | =2.2_rc2 | |
phpMyAdmin phpMyAdmin | =2.3.2 | |
phpMyAdmin phpMyAdmin | =2.5.4 | |
phpMyAdmin phpMyAdmin | =2.2.5 | |
phpMyAdmin phpMyAdmin | =2.2_rc3 | |
phpMyAdmin phpMyAdmin | =2.5.3 | |
phpMyAdmin phpMyAdmin | =2.2.2 | |
phpMyAdmin phpMyAdmin | =2.2.3 | |
phpMyAdmin phpMyAdmin | =2.5.5_rc2 | |
phpMyAdmin phpMyAdmin | =2.2_pre2 | |
phpMyAdmin phpMyAdmin | =2.6.3_pl1 | |
phpMyAdmin phpMyAdmin | =2.6.1_rc1 | |
phpMyAdmin phpMyAdmin | =2.7.0_beta1 | |
phpMyAdmin phpMyAdmin | =2.2_rc1 | |
phpMyAdmin phpMyAdmin | =2.0 | |
phpMyAdmin phpMyAdmin | =2.5.5_pl1 | |
phpMyAdmin phpMyAdmin | =2.0.5 | |
debian/phpmyadmin | 4:5.0.4+dfsg2-2+deb11u1 4:5.2.1+dfsg-1 | |
debian/phpmyadmin | <=4:2.6.2-3sarge1<=4:2.6.4-pl4-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3665 is classified as a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
To fix CVE-2005-3665, update phpMyAdmin to version 2.7.0 or later, which resolves the identified vulnerabilities.
CVE-2005-3665 exploits multiple cross-site scripting (XSS) vulnerabilities that allow remote attackers to inject arbitrary web scripts or HTML.
CVE-2005-3665 affects various versions of phpMyAdmin prior to 2.7.0, including versions 2.0, 2.1, 2.2, and 2.6.
Mitigation without updating is not recommended as it requires code changes to filter untrusted input adequately, making upgrading highly advisable.