CVE-2011-4634: XSS
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.8 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted database name, related to the Database Synchronize panel; (2) a crafted database name, related to the Database rename panel; (3) a crafted SQL query, related to the table overview panel; (4) a crafted SQL query, related to the view creation dialog; (5) a crafted column type, related to the table search dialog; or (6) a crafted column type, related to the create index dialog.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4634?
CVE-2011-4634 is considered a high severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2011-4634?
To fix CVE-2011-4634, upgrade phpMyAdmin to version 3.4.8 or later.
What types of attacks are possible with CVE-2011-4634?
CVE-2011-4634 allows remote attackers to execute arbitrary web scripts or HTML via crafted database names.
Which versions of phpMyAdmin are affected by CVE-2011-4634?
CVE-2011-4634 affects phpMyAdmin versions 3.4.0.0 to 3.4.7.0.
Is user input vulnerable to CVE-2011-4634?
Yes, user input for database names in certain panels is vulnerable to CVE-2011-4634.