|
|
Subscribe / Log in / New account

phpMyAdmin: cross-site scripting

Package(s):phpMyAdmin CVE #(s):CVE-2008-4775
Created:October 31, 2008 Updated:March 19, 2009
Description: From the CVE entry: Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.
Alerts:
Gentoo 200903-32 phpmyadmin 2009-03-18
Mandriva MDVSA-2009:026-1 phpMyAdmin 2009-02-26
Mandriva MDVSA-2009:026 phpMyAdmin 2009-01-23
Fedora FEDORA-2008-9336 phpMyAdmin 2008-10-31
Fedora FEDORA-2008-9316 phpMyAdmin 2008-10-31

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds