Unrated severityNVD Advisory· Published Nov 15, 2007· Updated Apr 23, 2026
CVE-2007-5977
CVE-2007-5977
Description
Cross-site scripting (XSS) vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to inject arbitrary web script or HTML via a hex-encoded IMG element in the db parameter in a POST request, a different vulnerability than CVE-2006-6942.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- secunia.com/advisories/27630nvdPatchVendor Advisory
- sourceforge.net/project/shownotes.phpnvdPatch
- www.phpmyadmin.net/home_page/security.phpnvdPatch
- secunia.com/advisories/27753nvdVendor Advisory
- www.digitrustgroup.com/advisories/tdg-advisory071108a.htmlnvd
- www.mandriva.com/security/advisoriesnvd
- www.securityfocus.com/bid/26512nvd
- www.vupen.com/english/advisories/2007/3824nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/38404nvd
- www.redhat.com/archives/fedora-package-announce/2007-November/msg00777.htmlnvd
News mentions
0No linked articles in our index yet.