|
|
| |
|
| |
phpmyadmin: multiple vulnerabilities
| Package(s): | phpmyadmin |
CVE #(s): | |
| Created: | October 16, 2012 |
Updated: | October 29, 2012 |
| Description: |
From the phpMyAdmin advisories [1], [2]:
[1] Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages. When creating/modifying a trigger, event or procedure with a crafted name, it is possible to trigger an XSS.
[2] Fetching the version information from a non-SSL site is vulnerable to a MITM attack. To display information about the current phpMyAdmin version on the main page, a piece of JavaScript is fetched from the phpmyadmin.net website in non-SSL mode. A man-in-the-middle could modify this script on the wire to cause mischief. |
| Alerts: |
|
( Log in to post comments)
|
|
|