CVE-2007-5589: XSS
Description of problem: PhpMyAdmin 2.11.1.1 was released on October 15th, 2007 and Fedora Development hangs still around the older 2.11.0. And the release 2.11.1.1 fixes a security issue: PMASA-2007-5
Version-Release number of selected component (if applicable): phpMyAdmin-2.11.0-1
Expected results: phpMyAdmin-2.11.1.1-1 or newer ;-)
Additional info: A simple version bump did the trick for me.
Other sources
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.11.1.2 allow remote attackers to inject arbitrary web script or HTML via certain input available in (1) PHPSELF in (a) serverstatus.php, and (b) grabglobals.lib.php, (c) displaychangepassword.lib.php, and (d) common.lib.php in libraries/; and certain input available in PHPSELF and (2) PATHINFO in libraries/common.inc.php. NOTE: there might also be other vectors related to (3) REQUESTURI.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5589?
CVE-2007-5589 is classified as a critical severity vulnerability that affects certain versions of phpMyAdmin.
How do I fix CVE-2007-5589?
To fix CVE-2007-5589, you should upgrade phpMyAdmin to version 2.11.1.1 or later.
Which versions of phpMyAdmin are affected by CVE-2007-5589?
CVE-2007-5589 affects phpMyAdmin versions prior to 2.11.1.1.
Is CVE-2007-5589 related to any other vulnerabilities?
Yes, CVE-2007-5589 is related to PMASA-2007-5, which addresses a security issue in older versions.
What are the consequences of not addressing CVE-2007-5589?
Failure to address CVE-2007-5589 can lead to unauthorized access and potential data breaches in applications using affected phpMyAdmin versions.