VDB
CVE-2010-4480
CVE-2010-4480
PUBLISHED
CVSS 4.300000190734863 MEDIUM
error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1, allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted BBcode tag containing "@" characters, as demonstrated using "[a@url@page]".
EPSS 7.45% · 91.9th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
7.45%
91.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| phpmyadmin | phpmyadmin | 3.3.8.1, 3.3.9.0 |
| n/a | n/a | * |
Timeline
- Dec 8, 2010 CVE Published
- Feb 4, 2022 EPSS Score
- May 17, 2022 CVE Updated
- Mar 7, 2023 EPSS Score
- Oct 26, 2024 EPSS Score
- Mar 17, 2025 EPSS Score
- Mar 18, 2025 EPSS Score
- Mar 29, 2025 EPSS Score
- Mar 30, 2025 EPSS Score
- May 1, 2025 EPSS Score
- May 9, 2025 EPSS Score
- May 12, 2025 EPSS Score
References
- ADV-2011-0027 vdb
- ADV-2011-0001 vdb
- 45633 vdb
- 42485 third-party-advisory
- DSA-2139 vendor-advisory
- 15699 exploit
- http://www.phpmyadmin.net/home_page/security/PMASA-2010-9.php url
- ADV-2010-3133 vdb
- 42725 third-party-advisory
- MDVSA-2011:000 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2010-4480 advisory