Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-12581

Опубликовано: 21 июн. 2018
Источник: debian
EPSS Низкий

Описание

An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted database name to trigger an XSS attack when that database is referenced from the Designer feature.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
phpmyadminfixed4:4.9.1+dfsg1-2package
phpmyadminnot-affectedstretchpackage
phpmyadminnot-affectedjessiepackage

Примечания

  • https://www.phpmyadmin.net/security/PMASA-2018-3/

  • https://github.com/phpmyadmin/phpmyadmin/commit/6943fff87324bd54c3a37a5160a5fb77498c355e

EPSS

Процентиль: 72%
0.00764
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 7 лет назад

An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted database name to trigger an XSS attack when that database is referenced from the Designer feature.

CVSS3: 6.1
nvd
около 7 лет назад

An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted database name to trigger an XSS attack when that database is referenced from the Designer feature.

CVSS3: 6.1
github
около 3 лет назад

phpMyAdmin XSS Vulnerability

suse-cvrf
около 7 лет назад

Security update for phpMyAdmin

suse-cvrf
около 7 лет назад

Security update for phpMyAdmin

EPSS

Процентиль: 72%
0.00764
Низкий