First published: Thu Aug 25 2011(Updated: )
From the upstream advisory: <a href="http://www.phpmyadmin.net/home_page/security/PMASA-2011-13.php">http://www.phpmyadmin.net/home_page/security/PMASA-2011-13.php</a> Announcement-ID: PMASA-2011-13 Date: 2011-08-24 Summary: Multiple XSS in the Tracking feature. Description: Missing sanitization on the table, column and index names leads to XSS vulnerabilities. Severity We consider this vulnerability to be serious. Mitigation factor: An attacker must be logged in via phpMyAdmin to exploit this problem. Affected Versions Versions 3.3.0 to 3.4.3.2 are affected. Solution: Upgrade to phpMyAdmin 3.3.10.4 or 3.4.4 or apply the related patch listed below. References This issue was found by Norman Hippert from The-Wildcat.de. Assigned CVE ids: <a href="https://access.redhat.com/security/cve/CVE-2011-3181">CVE-2011-3181</a> CWE ids: CWE-661 CWE-98
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyAdmin phpMyAdmin | =3.3.10.0 | |
phpMyAdmin phpMyAdmin | =3.3.8.1 | |
phpMyAdmin phpMyAdmin | =3.3.10.1 | |
phpMyAdmin phpMyAdmin | =3.3.3.0 | |
phpMyAdmin phpMyAdmin | =3.3.10.3 | |
phpMyAdmin phpMyAdmin | =3.3.4.0 | |
phpMyAdmin phpMyAdmin | =3.3.9.2 | |
phpMyAdmin phpMyAdmin | =3.3.1.0 | |
phpMyAdmin phpMyAdmin | =3.3.7 | |
phpMyAdmin phpMyAdmin | =3.3.5.0 | |
phpMyAdmin phpMyAdmin | =3.3.0.0 | |
phpMyAdmin phpMyAdmin | =3.3.6 | |
phpMyAdmin phpMyAdmin | =3.3.2.0 | |
phpMyAdmin phpMyAdmin | =3.3.9.0 | |
phpMyAdmin phpMyAdmin | =3.3.5.1 | |
phpMyAdmin phpMyAdmin | =3.3.9.1 | |
phpMyAdmin phpMyAdmin | =3.3.8 | |
phpMyAdmin phpMyAdmin | =3.3.10.2 | |
phpMyAdmin phpMyAdmin | =3.4.0.0 | |
phpMyAdmin phpMyAdmin | =3.4.3.1 | |
phpMyAdmin phpMyAdmin | =3.4.1.0 | |
phpMyAdmin phpMyAdmin | =3.4.2.0 | |
phpMyAdmin phpMyAdmin | =3.4.3.0 | |
phpMyAdmin phpMyAdmin | =3.4.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.