LWN.net Logo

phpMyAdmin: cross-site scripting

Package(s):phpmyadmin CVE #(s):CVE-2008-4326
Created:December 1, 2008 Updated:February 2, 2009
Description:

From the Debian advisory:

Masako Oono discovered that phpMyAdmin, a web-based administration interface for MySQL, insufficiently sanitises input allowing a remote attacker to gather sensitive data through cross site scripting, provided that the user uses the Internet Explorer web browser.

Alerts:
Debian DSA-1675-1 2008-11-30
SuSE SUSE-SR:2009:003 2009-02-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds