First published: Fri Mar 30 2012(Updated: )
An cross-site scripting (XSS) flaw was found in the way phpPgAdmin, a web-based PostgreSQL database administration tool, performed presentation of the default list of functions, being present in the database, to the user upon request. A remote attacker could provide a specially-crafted web page, which once visited by an unsuspecting, valid phpPgAdmin user could lead to arbitrary HTML or web script execution in the context of logged in phpPgAdmin user. References: [1] <a href="http://archives.postgresql.org/pgsql-announce/2012-03/msg00016.php">http://archives.postgresql.org/pgsql-announce/2012-03/msg00016.php</a> [2] <a href="https://github.com/phppgadmin/phppgadmin/commit/e92a003624609a445c4cf57c9c3d1fcef0eae47c#diff-0">https://github.com/phppgadmin/phppgadmin/commit/e92a003624609a445c4cf57c9c3d1fcef0eae47c#diff-0</a> Upstream patch: [3] <a href="https://github.com/phppgadmin/phppgadmin/commit/74174ad639664b52cc1609ede0af8bc403e98a00">https://github.com/phppgadmin/phppgadmin/commit/74174ad639664b52cc1609ede0af8bc403e98a00</a> CVE request: [4] <a href="http://www.openwall.com/lists/oss-security/2012/03/28/11">http://www.openwall.com/lists/oss-security/2012/03/28/11</a> CVE assignment: [5] <a href="http://www.openwall.com/lists/oss-security/2012/03/29/6">http://www.openwall.com/lists/oss-security/2012/03/29/6</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
phpPgAdmin | <=5.0.3 | |
phpPgAdmin | =5.0 | |
phpPgAdmin | =5.0.1 | |
phpPgAdmin | =5.0.2 | |
SUSE Linux | =11.4 | |
SUSE Linux | =12.1 | |
openSUSE | =11.4 | |
openSUSE | =12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1600 has been assigned a medium severity level due to its potential for exploitation via cross-site scripting.
To fix CVE-2012-1600, upgrade to phpPgAdmin version 5.0.4 or later, which addresses the XSS vulnerability.
CVE-2012-1600 affects phpPgAdmin versions up to and including 5.0.3.
Yes, CVE-2012-1600 can be exploited remotely by attackers through specially crafted web pages.
CVE-2012-1600 is classified as a cross-site scripting (XSS) vulnerability.