LWN.net Logo

phpMyAdmin: cross-site scripting

Package(s):phpMyAdmin CVE #(s):CVE-2011-4634
Created:December 19, 2011 Updated:January 2, 2012
Description: From the Red Hat advisory:

Using crafted database names, it was possible to produce XSS in the Database Synchronize and Database rename panels. Using an invalid and crafted SQL query, it was possible to produce XSS when editing a query on a table overview panel or when using the view creation dialog. Using a crafted column type, it was possible to produce XSS in the table search and create index dialogs.

Only phpMyAdmin 3.4.x is affected by this vulnerability.

Alerts:
Fedora FEDORA-2011-16786 2011-12-04
Fedora FEDORA-2011-16768 2011-12-04
Mandriva MDVSA-2011:198 2011-12-31
Gentoo 201201-01 2012-01-04

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds