LWN.net Logo

phppgadmin: cross-site scripting

Package(s):phppgadmin CVE #(s):CVE-2012-1600
Created:April 12, 2012 Updated:April 18, 2012
Description:

From the Red Hat Bugzilla entry:

An cross-site scripting (XSS) flaw was found in the way phpPgAdmin, a web-based PostgreSQL database administration tool, performed presentation of the default list of functions, being present in the database, to the user upon request. A remote attacker could provide a specially-crafted web page, which once visited by an unsuspecting, valid phpPgAdmin user could lead to arbitrary HTML or web script execution in the context of logged in phpPgAdmin user.

Alerts:
openSUSE openSUSE-SU-2012:0493-1 2012-04-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds