Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-5274

Опубликовано: 22 авг. 2014
Источник: debian

Описание

Cross-site scripting (XSS) vulnerability in the view operations page in phpMyAdmin 4.1.x before 4.1.14.3 and 4.2.x before 4.2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted view name, related to js/functions.js.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
phpmyadminfixed4:4.2.7.1-1package
phpmyadminnot-affectedwheezypackage
phpmyadminnot-affectedsqueezepackage

Примечания

  • https://www.phpmyadmin.net/security/PMASA-2014-9/

  • Version 3.x uses the browser-provided confirmation window and not custom HTML.

Связанные уязвимости

ubuntu
больше 11 лет назад

Cross-site scripting (XSS) vulnerability in the view operations page in phpMyAdmin 4.1.x before 4.1.14.3 and 4.2.x before 4.2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted view name, related to js/functions.js.

nvd
больше 11 лет назад

Cross-site scripting (XSS) vulnerability in the view operations page in phpMyAdmin 4.1.x before 4.1.14.3 and 4.2.x before 4.2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted view name, related to js/functions.js.

github
больше 3 лет назад

phpMyAdmin cross-site scripting vulnerability in crafted view name