Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-5274

Опубликовано: 22 авг. 2014
Источник: debian
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in the view operations page in phpMyAdmin 4.1.x before 4.1.14.3 and 4.2.x before 4.2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted view name, related to js/functions.js.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
phpmyadminfixed4:4.2.7.1-1package
phpmyadminnot-affectedwheezypackage
phpmyadminnot-affectedsqueezepackage

Примечания

  • https://www.phpmyadmin.net/security/PMASA-2014-9/

  • Version 3.x uses the browser-provided confirmation window and not custom HTML.

EPSS

Процентиль: 40%
0.00174
Низкий

Связанные уязвимости

ubuntu
почти 11 лет назад

Cross-site scripting (XSS) vulnerability in the view operations page in phpMyAdmin 4.1.x before 4.1.14.3 and 4.2.x before 4.2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted view name, related to js/functions.js.

nvd
почти 11 лет назад

Cross-site scripting (XSS) vulnerability in the view operations page in phpMyAdmin 4.1.x before 4.1.14.3 and 4.2.x before 4.2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted view name, related to js/functions.js.

github
около 3 лет назад

phpMyAdmin cross-site scripting vulnerability in crafted view name

EPSS

Процентиль: 40%
0.00174
Низкий