CVE-2007-5589: XSS

Published Oct 16, 2007
·
Updated

Description of problem: PhpMyAdmin 2.11.1.1 was released on October 15th, 2007 and Fedora Development hangs still around the older 2.11.0. And the release 2.11.1.1 fixes a security issue: PMASA-2007-5

Version-Release number of selected component (if applicable): phpMyAdmin-2.11.0-1

Expected results: phpMyAdmin-2.11.1.1-1 or newer ;-)

Additional info: A simple version bump did the trick for me.

Other sources

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.11.1.2 allow remote attackers to inject arbitrary web script or HTML via certain input available in (1) PHPSELF in (a) serverstatus.php, and (b) grabglobals.lib.php, (c) displaychangepassword.lib.php, and (d) common.lib.php in libraries/; and certain input available in PHPSELF and (2) PATHINFO in libraries/common.inc.php. NOTE: there might also be other vectors related to (3) REQUESTURI.

MITRE

Affected Software

2 affected componentsFixes available
redhat/2.11.2.2<1.
1.
phpMyAdmin phpMyAdmin<=2.11.1.1

Event History

Oct 19, 2007
CVE Published
11:17 PM
Oct 20, 2007
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2007-5589?

CVE-2007-5589 is classified as a critical severity vulnerability that affects certain versions of phpMyAdmin.

2

How do I fix CVE-2007-5589?

To fix CVE-2007-5589, you should upgrade phpMyAdmin to version 2.11.1.1 or later.

3

Which versions of phpMyAdmin are affected by CVE-2007-5589?

CVE-2007-5589 affects phpMyAdmin versions prior to 2.11.1.1.

4

Is CVE-2007-5589 related to any other vulnerabilities?

Yes, CVE-2007-5589 is related to PMASA-2007-5, which addresses a security issue in older versions.

5

What are the consequences of not addressing CVE-2007-5589?

Failure to address CVE-2007-5589 can lead to unauthorized access and potential data breaches in applications using affected phpMyAdmin versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203