LWN.net Logo

phpMyAdmin: cross-site scripting

Package(s):phpMyAdmin CVE #(s):CAN-2004-1055
Created:November 29, 2004 Updated:December 1, 2004
Description: Cedric Cochin has discovered multiple cross-site scripting vulnerabilities in phpMyAdmin. These vulnerabilities can be exploited through the PmaAbsoluteUri parameter, the zero_rows parameter in read_dump.php, the confirm form, or an error message generated by the internal phpMyAdmin parser. By sending a specially-crafted request, an attacker can inject and execute malicious script code, potentially compromising the victim's browser.
Alerts:
Gentoo 200411-36 2004-11-27

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds