LWN.net Logo

phpmyadmin: multiple vulnerabilities

Package(s):phpmyadmin CVE #(s):CVE-2010-4480 CVE-2010-4481
Created:December 31, 2010 Updated:March 30, 2011
Description: From the Debian advisory:

Cross site scripting was possible in errors, that allowed a remote attacker to inject arbitrary web script or HTML. (CVE-2010-4480)

Display of PHP's phpinfo() function was available to world, but only if this functionality had been enabled (defaults to off). This may leak some information about the host system. (CVE-2010-4481)

Alerts:
Fedora FEDORA-2011-3737 2011-03-21
Fedora FEDORA-2011-3733 2011-03-21
Pardus 2011-19 2011-01-31
Mandriva MDVSA-2011:000 2011-01-05
Debian DSA-2139-1 2010-12-31

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds