Back to Database
Status published
Medium
CVE-2009-2284
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote...
Vulnerability Description
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-2284
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00256.html
- http://www.phpmyadmin.net/home_page/security/PMASA-2009-5.php
- https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00152.html
- http://secunia.com/advisories/35715
- http://secunia.com/advisories/35649
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:192
- https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00150.html
More from phpmyadmin
View All →CVE-2022-23808
An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An...
Unknown
0
CVE-2022-23807
An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and...
Medium
4.3
CVE-2020-5504
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL...
High
8.8
CVE-2020-26935
An issue was discovered in SearchController in phpMyAdmin before 4.9.6...
Critical
9.8
CVE-2020-26934
phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through...
Medium
6.1
Affected Vendor
phpmyadmin
View all reports →Affected Software
phpmyadmin
Vulnerable Versions:
0, 2.0, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.1, 2.1.0, 2.1.1, 2.1.2, 2.2, 2.2.0, 2.2.0_pre1, 2.2.0_pre2, 2.2.0_rc1, 2.2.0_rc2, 2.2.0_rc3, 2.2.2, 2.2.3, 2.2.4, 2.2.5, 2.2.6, 2.2.7_pl1, 2.2_pre1, 2.2_pre2, 2.2_rc1, 2.2_rc2, 2.2_rc3, 2.3.1, 2.3.2, 2.4.0, 2.5.0, 2.5.1, 2.5.2, 2.5.2_pl1, 2.5.3, 2.5.4, 2.5.5, 2.5.5_pl1, 2.5.5_rc1, 2.5.5_rc2, 2.5.6_rc1, 2.5.6_rc2, 2.5.7, 2.5.7_pl1, 2.6.0_pl1, 2.6.0_pl2, 2.6.0_pl3, 2.6.1, 2.6.1_pl1, 2.6.1_pl3, 2.6.1_rc1, 2.6.2, 2.6.2_dev, 2.6.2_pl1, 2.6.2_rc1, 2.6.3, 2.6.3_pl1, 2.6.4, 2.6.4_pl1, 2.6.4_pl2, 2.6.4_pl3, 2.6.4_pl4, 2.6.4_rc1, 2.7, 2.7.0, 2.7.0_beta1, 2.7.0_pl1, 2.7.0_pl2, 2.7.0_rc1, 2.7_pl1, 2.8.0, 2.8.0.1, 2.8.0.2, 2.8.0.3, 2.8.1, 2.8.1_dev, 2.8.2, 2.8.3, 2.8.4, 2.9, 2.9.0, 2.9.0.1, 2.9.0.2, 2.9.0.3, 2.9.0_beta1, 2.9.0_dev, 2.9.0_rc1, 2.9.1, 2.9.1.1, 2.9.1_rc1, 2.9.1_rc2, 2.9.2, 2.9_rc1, 2.10.0, 2.10.0.0, 2.10.0.1, 2.10.0.2, 2.10.1, 2.10.01, 2.10.1.0, 2.10.2, 2.10.2.0, 2.10.3, 2.10.3.0, 2.10.3rc1, 2.11.0, 2.11.0.0, 2.11.0beta1, 2.11.0rc1, 2.11.1, 2.11.1.0, 2.11.1.1, 2.11.1.2, 2.11.1rc1, 2.11.2, 2.11.2.0, 2.11.2.1, 2.11.2.2, 2.11.3, 2.11.3.0, 2.11.3rc1, 2.11.4, 2.11.4.0, 2.11.4rc1, 2.11.5, 2.11.5.0, 2.11.5.1, 2.11.5.2, 2.11.5rc1, 2.11.6, 2.11.6.0, 2.11.6rc1, 2.11.7, 2.11.7.0, 2.11.8, 2.11.9, 2.11.9.0, 2.11.9.1, 2.11.9.2, 2.11.9.3, 2.11.9.4, 3.0.0, 3.0.0-alpha, 3.0.0-beta, 3.0.0-rc1, 3.0.1, 3.0.1-rc1, 3.0.1.1, 3.1.0, 3.1.0-beta1, 3.1.0.0, 3.1.1, 3.1.2, 3.1.3, 3.1.3-rc1, 3.1.3.1, 3.1.3.2, 3.1.4, 3.1.4-rc2, 3.1.5, 3.1.5-rc1, 3.2.0-beta1, 3.2.0-rc1
Timeline
Official Publish:
July 1st, 2009
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.