CVE-2005-2869
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 5.1%
from disclosure to weapon0 days
Published on NVDSep 8
1st PoCAug 28
exploitation probability
5.1%top 8% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/26199⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://secunia.com/advisories/16605http://secunia.com/advisories/17337http://secunia.com/advisories/17559http://secunia.com/advisories/17607http://sourceforge.net/tracker/index.php?func=detail&aid=1240880&group_id=23067&atid=377408http://sourceforge.net/tracker/index.php?func=detail&aid=1265740&group_id=23067&atid=377408http://www.debian.org/security/2005/dsa-880http://www.novell.com/linux/security/advisories/2005_28_sr.htmlhttp://www.novell.com/linux/security/advisories/2005_66_phpmyadmin.html