|
|
Log in / Subscribe / Register

phpMyAdmin: cross-site scripting

Package(s):phpMyAdmin CVE #(s):CVE-2011-4634
Created:December 19, 2011 Updated:January 2, 2012
Description: From the Red Hat advisory:

Using crafted database names, it was possible to produce XSS in the Database Synchronize and Database rename panels. Using an invalid and crafted SQL query, it was possible to produce XSS when editing a query on a table overview panel or when using the view creation dialog. Using a crafted column type, it was possible to produce XSS in the table search and create index dialogs.

Only phpMyAdmin 3.4.x is affected by this vulnerability.

Alerts:
Gentoo 201201-01 phpmyadmin 2012-01-04
Mandriva MDVSA-2011:198 phpmyadmin 2011-12-31
Fedora FEDORA-2011-16786 phpMyAdmin 2011-12-04
Fedora FEDORA-2011-16768 phpMyAdmin 2011-12-04

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds