Unrated severityNVD Advisory· Published Nov 15, 2007· Updated Jun 16, 2026
CVE-2007-5977
CVE-2007-5977
Description
Cross-site scripting (XSS) vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to inject arbitrary web script or HTML via a hex-encoded IMG element in the db parameter in a POST request, a different vulnerability than CVE-2006-6942.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:*range: <=2.11.2
- (no CPE)range: <2.11.2.1
Patches
Vulnerability mechanics
References
10- secunia.com/advisories/27630nvdPatchVendor Advisory
- sourceforge.net/project/shownotes.phpnvdPatch
- www.phpmyadmin.net/home_page/security.phpnvdPatch
- secunia.com/advisories/27753nvdVendor Advisory
- www.digitrustgroup.com/advisories/tdg-advisory071108a.htmlnvd
- www.mandriva.com/security/advisoriesnvd
- www.securityfocus.com/bid/26512nvd
- www.vupen.com/english/advisories/2007/3824nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/38404nvd
- www.redhat.com/archives/fedora-package-announce/2007-November/msg00777.htmlnvd
News mentions
0No linked articles in our index yet.