Description
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.7.0 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP_HOST variable and (2) various scripts in the libraries directory that handle header generation.
Remediation
References
Related Vulnerabilities
MyBB Improper Input Validation Vulnerability (CVE-2008-4930)
TYPO3 Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-2717)
Plone CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-5492)
WordPress Plugin Comment Rating 'id' Parameter SQL Injection (2.9.23)