CVE-2012-4345: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Database Structure page in phpMyAdmin 3.4.x before 3.4.11.1 and 3.5.x before 3.5.2.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) a crafted table name during table creation, or a (2) Empty link or (3) Drop link for a crafted table name.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4345?
CVE-2012-4345 has a medium severity rating due to the potential for authenticated users to execute malicious scripts.
How do I fix CVE-2012-4345?
To fix CVE-2012-4345, upgrade phpMyAdmin to version 3.4.11.1 or 3.5.2.2 or later.
Who is affected by CVE-2012-4345?
CVE-2012-4345 affects users of phpMyAdmin versions 3.4.x before 3.4.11.1 and 3.5.x before 3.5.2.2.
What types of attacks can be performed using CVE-2012-4345?
CVE-2012-4345 allows attackers to conduct Cross-Site Scripting (XSS) attacks via crafted table names or other inputs.
Is CVE-2012-4345 easy to exploit?
CVE-2012-4345 can be exploited relatively easily by authenticated users, making it important to apply updates quickly.