CVE-2011-1940: XSS
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.3.x before 3.3.10.1 and 3.4.x before 3.4.1 allow remote attackers to inject arbitrary web script or HTML via a crafted table name that triggers improper HTML rendering on a Tracking page, related to (1) libraries/tbllinks.inc.php and (2) tbltracking.php.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1940?
CVE-2011-1940 is rated as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2011-1940?
To resolve CVE-2011-1940, upgrade phpMyAdmin to version 3.3.10.1 or 3.4.1 or later.
What are the affected versions of phpMyAdmin for CVE-2011-1940?
The affected versions include phpMyAdmin 3.3.x before 3.3.10.1 and 3.4.x before 3.4.1.
What type of vulnerability is CVE-2011-1940?
CVE-2011-1940 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject malicious scripts.
Can CVE-2011-1940 lead to data compromise?
Yes, successful exploitation of CVE-2011-1940 can potentially allow attackers to execute scripts in the context of the user's session, leading to data compromise.