CVE-2010-2958: XSS
Cross-site scripting (XSS) vulnerability in libraries/Error.class.php in phpMyAdmin 3.x before 3.3.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to a PHP backtrace and error messages (aka debugging messages), a different vulnerability than CVE-2010-3056.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2958?
CVE-2010-2958 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2010-2958?
To fix CVE-2010-2958, upgrade phpMyAdmin to version 3.3.6 or later.
What versions of phpMyAdmin are affected by CVE-2010-2958?
CVE-2010-2958 affects phpMyAdmin versions before 3.3.6, including 3.0.1.1, 3.1.0, and any version prior to 3.3.6.
What kind of attack can CVE-2010-2958 allow?
CVE-2010-2958 allows remote attackers to inject arbitrary web script or HTML through error messages.
Can I take preventive measures against CVE-2010-2958?
Yes, to prevent CVE-2010-2958, ensure phpMyAdmin is regularly updated and consider implementing web application firewalls.