CVE-2010-2958

medium
Published 2010-09-08 · Modified 2025-04-12
CVSS v3
CVSS v2
4.3
VIR risk
4.3

Description

Cross-site scripting (XSS) vulnerability in libraries/Error.class.php in phpMyAdmin 3.x before 3.3.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to a PHP backtrace and error messages (aka debugging messages), a different vulnerability than CVE-2010-3056.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2010-2958

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.vupen.com/english/advisories/2010/2242

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.phpmyadmin.net/home_page/security/PMASA-2010-6.php

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/41206

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed4:3.3.6-1
debian debianbullseyefixed4:3.3.6-1
debian debiansidfixed4:3.3.6-1
debian debiantrixiefixed4:3.3.6-1

Package impact

EcosystemPackageVulnerableFixed
php Packagistphpmyadmin/phpmyadmin>=3.0.0,<3.3.63.3.6

Application impact

VendorProductVersionsFixed
phpmyadminphpmyadmin3.0.0
phpmyadminphpmyadmin3.0.1
phpmyadminphpmyadmin3.0.1.1
phpmyadminphpmyadmin3.1.0
phpmyadminphpmyadmin3.1.1
phpmyadminphpmyadmin3.1.2
phpmyadminphpmyadmin3.1.3
phpmyadminphpmyadmin3.1.3.1
phpmyadminphpmyadmin3.1.3.2
phpmyadminphpmyadmin3.1.4
phpmyadminphpmyadmin3.1.5
phpmyadminphpmyadmin3.2.0
phpmyadminphpmyadmin3.2.1
phpmyadminphpmyadmin3.2.2
phpmyadminphpmyadmin3.3.0.0
phpmyadminphpmyadmin3.3.1.0
phpmyadminphpmyadmin3.3.2.0
phpmyadminphpmyadmin3.3.3.0
phpmyadminphpmyadmin3.3.4.0
phpmyadminphpmyadmin3.3.5.0
phpmyadminphpmyadmin3.3.5.1

References

CWEs

CWE-79

Verify integrity in audit chain (admin only). AS-IS.