LWN.net Logo

phpmyadmin: multiple vulnerabilities

Package(s):phpmyadmin CVE #(s):CVE-2013-4995 CVE-2013-4996 CVE-2013-4998 CVE-2013-5000 CVE-2013-5002 CVE-2013-5003
Created:July 30, 2013 Updated:July 31, 2013
Description: From the Mandriva advisory:

* XSS due to unescaped HTML Output when executing a SQL query (CVE-2013-4995).

* 5 XSS vulnerabilities in setup, chart display, process list, and logo link. If a crafted version.json would be presented, an XSS could be introduced (CVE-2013-4996).

* Full path disclosure vulnerabilities (CVE-2013-4998, CVE-2013-5000).

* Self-XSS due to unescaped HTML output in schema export (CVE-2013-5002).

* SQL injection vulnerabilities, producing a privilege escalation (control user) (CVE-2013-5003).

Alerts:
Mandriva MDVSA-2013:203 2013-07-30
Mageia MGASA-2013-0238 2013-07-29

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds