S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2007-5728 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in phpPgAdmin affects v. 3.5 to 4.1.1, and possibly 4.1.2.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.5k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2007-5728
4.3
CVSS

Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, allows remote attackers to inject arbitrary web script or HTML via certain input available in PHP_SELF in (1) redirect.php, possibly related to (2) login.php, different vectors than CVE-2007-2865.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 18, 2026View on NVD →
Detail

PhpPgAdmin is a web-based administration tool for PostgreSQL databases. It provides a user-friendly interface for managing PostgreSQL databases, including creating tables, running SQL queries, and managing user accounts. The tool is widely used by database administrators and developers for managing their PostgreSQL databases.

CVE-2007-5728 is a cross-site scripting (XSS) vulnerability that was detected in phpPgAdmin versions 3.5 to 4.1.1, and possibly 4.1.2. The vulnerability allows remote attackers to inject arbitrary web scripts or HTML codes through certain input fields available in PHP_SELF such as redirect.php and login.php. This particular vulnerability is different from CVE-2007-2865, which had been previously detected in phpPgAdmin.

When exploited, the CVE-2007-5728 vulnerability can enable an attacker to run malicious code or scripts on the user's browser, allowing the hacker to hijack sensitive information such as login credentials and personal data. The attacker could also redirect users to malicious websites that could download malware or hijack the user's web browser. Furthermore, the hacker could use the exploit to gain access to the database server's network or even the entire system.

If you are concerned about vulnerabilities in your digital assets, s4e.io can help. Our pro features offer comprehensive vulnerability scanning and reporting, allowing you to quickly and easily uncover any security risks in your web applications, network, or servers. With s4e.io, you can rest assured that your digital assets are protected from potential threats and exploits.

 

REFERENCES

Solution Advice

To protect against this vulnerability, administrators need to ensure that their systems are running the latest versions of PhpPgAdmin. Additionally, other security precautions can be taken to reduce the risks associated with XSS vulnerability attacks. These precautions include:

  • Sanitize user input to prevent any malicious code from entering the system
  • Implement strict input validation checks for forms and user-generated content
  • Enable web application firewalls and intrusion detection systems 
  • Conduct regular security audits to identify any security gaps

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.