First published: Tue Aug 21 2012(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the Database Structure page in phpMyAdmin 3.4.x before 3.4.11.1 and 3.5.x before 3.5.2.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) a crafted table name during table creation, or a (2) Empty link or (3) Drop link for a crafted table name.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyAdmin phpMyAdmin | =3.4.0.0 | |
phpMyAdmin phpMyAdmin | =3.4.1.0 | |
phpMyAdmin phpMyAdmin | =3.4.2.0 | |
phpMyAdmin phpMyAdmin | =3.4.3.0 | |
phpMyAdmin phpMyAdmin | =3.4.3.1 | |
phpMyAdmin phpMyAdmin | =3.4.3.2 | |
phpMyAdmin phpMyAdmin | =3.4.4.0 | |
phpMyAdmin phpMyAdmin | =3.4.5.0 | |
phpMyAdmin phpMyAdmin | =3.4.6.0 | |
phpMyAdmin phpMyAdmin | =3.4.7.0 | |
phpMyAdmin phpMyAdmin | =3.4.7.1 | |
phpMyAdmin phpMyAdmin | =3.4.8.0 | |
phpMyAdmin phpMyAdmin | =3.4.9.0 | |
phpMyAdmin phpMyAdmin | =3.4.10.0 | |
phpMyAdmin phpMyAdmin | =3.4.10.1 | |
phpMyAdmin phpMyAdmin | =3.4.10.2 | |
phpMyAdmin phpMyAdmin | =3.4.11 | |
phpMyAdmin phpMyAdmin | =3.5.0.0 | |
phpMyAdmin phpMyAdmin | =3.5.1.0 | |
phpMyAdmin phpMyAdmin | =3.5.2.0 | |
phpMyAdmin phpMyAdmin | =3.5.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.