LWN.net Logo

phpmyadmin: multiple vulnerabilities

Package(s):phpmyadmin CVE #(s):
Created:October 16, 2012 Updated:October 29, 2012
Description: From the phpMyAdmin advisories [1], [2]:

[1] Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages. When creating/modifying a trigger, event or procedure with a crafted name, it is possible to trigger an XSS.

[2] Fetching the version information from a non-SSL site is vulnerable to a MITM attack. To display information about the current phpMyAdmin version on the main page, a piece of JavaScript is fetched from the phpmyadmin.net website in non-SSL mode. A man-in-the-middle could modify this script on the wire to cause mischief.

Alerts:
Mageia MGASA-2012-0298 2012-10-16
Fedora FEDORA-2012-15754 2012-10-28
Fedora FEDORA-2012-15725 2012-10-28

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds