CVE-2013-4995: XSS
Cross-site scripting (XSS) vulnerability in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted SQL query that is not properly handled during the display of row information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4995?
The severity of CVE-2013-4995 is considered medium due to the potential for unauthorized script injection by remote authenticated users.
How do I fix CVE-2013-4995?
To fix CVE-2013-4995, upgrade to phpMyAdmin version 3.5.8.2 or later, or 4.0.4.2 or later.
Who is affected by CVE-2013-4995?
CVE-2013-4995 affects phpMyAdmin versions 3.5.x prior to 3.5.8.2 and 4.0.x prior to 4.0.4.2.
What types of attacks can be executed due to CVE-2013-4995?
CVE-2013-4995 enables attackers to execute cross-site scripting (XSS) attacks by injecting malicious scripts via SQL queries.
Is there a workaround for CVE-2013-4995 if I cannot upgrade?
There are no known workarounds for CVE-2013-4995; upgrading to a patched version is the only recommended solution.