CVE-2010-4480: XSS
Published Dec 8, 2010
·Updated
error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1, allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted BBcode tag containing "@" characters, as demonstrated using "[a@url@page]".
Affected Software
2 affected components
phpMyAdmin phpMyAdmin=3.3.8.1
phpMyAdmin phpMyAdmin=3.3.9.0
Event History
Dec 8, 2010
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4480?
CVE-2010-4480 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2010-4480?
To fix CVE-2010-4480, upgrade PhpMyAdmin to version 3.4.0-beta1 or later to eliminate the vulnerability.
3
What type of attack does CVE-2010-4480 allow?
CVE-2010-4480 allows remote attackers to conduct cross-site scripting (XSS) attacks.
4
Which versions of PhpMyAdmin are affected by CVE-2010-4480?
CVE-2010-4480 affects PhpMyAdmin versions before 3.4.0-beta1, including 3.3.8.1 and 3.3.9.0.
5
What is the nature of the XSS vulnerability in CVE-2010-4480?
The XSS vulnerability in CVE-2010-4480 is caused by improper handling of crafted BBcode tags containing '@' characters.