LWN.net Logo

phpMyAdmin: cross-site scripting

Package(s):phpMyAdmin CVE #(s):
Created:June 25, 2008 Updated:June 25, 2008
Description: phpMyAdmin suffers from cross-site scripting vulnerabilities in several library scripts. From the advisory: "We were able to reproduce this only on systems where both of these conditions are true: the PHP register_globals setting is 'on' and the web server does not apply the settings contained in the .htaccess file that we placed in /libraries."
Alerts:
Fedora FEDORA-2008-5676 2008-06-25
Fedora FEDORA-2008-5640 2008-06-25

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds