CVE-2014-8326: XSS
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.5, 4.1.x before 4.1.14.6, and 4.2.x before 4.2.10.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name, related to the libraries/DatabaseInterface.class.php code for SQL debug output and the js/serverstatusmonitor.js code for the server monitor page.
Other sources
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.5, 4.1.x before 4.1.14.6, and 4.2.x before 4.2.10.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name, related to the libraries/DatabaseInterface.class.php code for SQL debug output and the js/serverstatusmonitor.js code for the server monitor page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8326?
The severity of CVE-2014-8326 is classified as medium, as it exposes applications to cross-site scripting attacks.
How do I fix CVE-2014-8326?
To fix CVE-2014-8326, upgrade phpMyAdmin to version 4.0.10.5, 4.1.14.6, or 4.2.10.1 or higher.
Which versions are affected by CVE-2014-8326?
CVE-2014-8326 affects phpMyAdmin versions prior to 4.0.10.5, 4.1.14.6, and 4.2.10.1.
What types of attacks can CVE-2014-8326 facilitate?
CVE-2014-8326 can facilitate cross-site scripting (XSS) attacks, allowing the injection of arbitrary web scripts.
Who is impacted by CVE-2014-8326?
Users of phpMyAdmin versions earlier than the specified remedy versions are impacted by CVE-2014-8326.