|
|
| |
|
| |
phpMyAdmin: cross-site scripting
| Package(s): | phpMyAdmin |
CVE #(s): | CVE-2011-4634
|
| Created: | December 19, 2011 |
Updated: | January 2, 2012 |
| Description: |
From the Red Hat advisory:
Using crafted database names, it was possible to produce XSS in the Database
Synchronize and Database rename panels. Using an invalid and crafted SQL query,
it was possible to produce XSS when editing a query on a table overview panel
or when using the view creation dialog. Using a crafted column type, it was
possible to produce XSS in the table search and create index dialogs.
Only phpMyAdmin 3.4.x is affected by this vulnerability. |
| Alerts: |
|
( Log in to post comments)
|
|
|