First published: Thu Sep 15 2011(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via a crafted row that triggers an improperly constructed confirmation message after inline-editing and save operations, related to (1) `js/functions.js` and (2) `js/tbl_structure.js`.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/phpmyadmin/phpmyadmin | >=3.4.0<3.4.5 | 3.4.5 |
phpMyAdmin phpMyAdmin | =3.4.0.0 | |
phpMyAdmin phpMyAdmin | =3.4.1.0 | |
phpMyAdmin phpMyAdmin | =3.4.2.0 | |
phpMyAdmin phpMyAdmin | =3.4.3.0 | |
phpMyAdmin phpMyAdmin | =3.4.3.1 | |
phpMyAdmin phpMyAdmin | =3.4.3.2 | |
phpMyAdmin phpMyAdmin | =3.4.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.