Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-4954

Опубликовано: 20 июл. 2014
Источник: ubuntu
Приоритет: medium
CVSS2: 3.5

Описание

Cross-site scripting (XSS) vulnerability in the PMA_getHtmlForActionLinks function in libraries/structure.lib.php in phpMyAdmin 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrary web script or HTML via a crafted table comment that is improperly handled during construction of a database structure page.

РелизСтатусПримечание
devel

not-affected

4:4.2.6-1
esm-infra-legacy/trusty

not-affected

lucid

not-affected

precise

not-affected

trusty

not-affected

trusty/esm

not-affected

upstream

released

4.2.6
utopic

not-affected

4:4.2.6-1

Показывать по

3.5 Low

CVSS2

Связанные уязвимости

nvd
почти 11 лет назад

Cross-site scripting (XSS) vulnerability in the PMA_getHtmlForActionLinks function in libraries/structure.lib.php in phpMyAdmin 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrary web script or HTML via a crafted table comment that is improperly handled during construction of a database structure page.

debian
почти 11 лет назад

Cross-site scripting (XSS) vulnerability in the PMA_getHtmlForActionLi ...

github
около 3 лет назад

Cross-site scripting (XSS) vulnerability in the PMA_getHtmlForActionLinks function in libraries/structure.lib.php in phpMyAdmin 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrary web script or HTML via a crafted table comment that is improperly handled during construction of a database structure page.

3.5 Low

CVSS2

Уязвимость CVE-2014-4954