.. / CVE-2007-5728

Exploit for phpPgAdmin <=4.1.1 - Cross-Site Scripting (CVE-2007-5728)

Description:

phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, is vulnerable to cross-site scripting and allows remote attackers to inject arbitrary web script or HTML via certain input available in PHP_SELF in (1) redirect.php, possibly related to (2) login.php, which are different vectors than CVE-2007-2865.

Nuclei Template

View the template here CVE-2007-5728.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2007/CVE-2007-5728.yaml
Copy

References:

http://www.debian.org/security/2008/dsa-1693
http://www.novell.com/linux/security/advisories/2007_24_sr.html
https://nvd.nist.gov/vuln/detail/CVE-2007-5728
https://www.exploit-db.com/exploits/30090
http://lists.grok.org.uk/pipermail/full-disclosure/2007-May/063617.html