Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerChoice parameters in select_server.lib.php, (2) the bg_color or row_no parameters in display_tbl_links.lib.php, the left_font_family parameter in theme_left.css.php, or the right_font_family parameter in theme_right.css.php.
CVSS Details
- CVSS 3.1 Base Score: 6.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade phpmyadmin | Jul 30, 2024 | Feb 24, 2005 |
| Freebsd | — | Upgrade phpMyAdmin | Dec 10, 2025 | Mar 8, 2005 |
| Gentoo Linux | — | Upgrade dev-db/phpmyadmin. | Oct 30, 2017 | Feb 24, 2005 |
| Phpmyadmin | — | Upgrade phpMyAdmin to the latest version | Oct 16, 2019 | Feb 24, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub