LWN.net Logo

phpMyAdmin: cross-site scripting

Package(s):phpMyAdmin CVE #(s):CVE-2010-3263
Created:September 10, 2010 Updated:September 21, 2010
Description: From the Red Hat bugzilla:

phpMyAdmin (x < v3.3.7) improperly sanitized server name provided to the setup script. An attacker could use this flaw (under certain installations) to conduct cross-site scripting (XSS) attacks (execute arbitrary HTML or scripting code).

Alerts:
Mandriva MDVSA-2010:186 2010-09-21
Fedora FEDORA-2010-14411 2010-09-10
Fedora FEDORA-2010-14426 2010-09-10
Gentoo 201201-01 2012-01-04

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds