phpMoAdmin Reflected Cross-Site Scripting Vulnerability
Vulnerability
A reflected cross-site scripting vulnerability has been identified in phpMoAdmin version 1.1.5. This issue allows unauthenticated attackers to inject malicious scripts by manipulating the 'newdb' parameter in 'moadmin.php'. When users click on the crafted link, the injected JavaScript payload is executed in their browsers, potentially leading to arbitrary code execution.
Impact
Exploitation of this vulnerability allows for reflected cross-site scripting, where injected scripts are executed in the context of the user's browser.
Reproduction
To reproduce this vulnerability, send a GET request to 'moadmin.php' with the 'newdb' parameter containing the injected script, such as a JavaScript 'alert' payload. This can be done by crafting a URL that includes the malicious script in the 'newdb' parameter.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
