Lucene search

K
cve[email protected]CVE-2014-1879
HistoryFeb 20, 2014 - 3:27 p.m.

CVE-2014-1879

2014-02-2015:27:09
CWE-79
web.nvd.nist.gov
40
cve-2014-1879
cross-site scripting
xss
phpmyadmin
vulnerability
import.php
nvd

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5

Confidence

High

EPSS

0.002

Percentile

51.4%

Cross-site scripting (XSS) vulnerability in import.php in phpMyAdmin before 4.1.7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename in an import action.

Affected configurations

NVD
Node
phpmyadminphpmyadminRange4.1.6
OR
phpmyadminphpmyadminMatch1.0.0
OR
phpmyadminphpmyadminMatch1.0.1
OR
phpmyadminphpmyadminMatch1.0.2
OR
phpmyadminphpmyadminMatch1.0.3
OR
phpmyadminphpmyadminMatch1.0.4
OR
phpmyadminphpmyadminMatch1.0.5
OR
phpmyadminphpmyadminMatch1.0.6
OR
phpmyadminphpmyadminMatch1.0.6a
OR
phpmyadminphpmyadminMatch1.0.7
OR
phpmyadminphpmyadminMatch1.0.8
OR
phpmyadminphpmyadminMatch1.1
OR
phpmyadminphpmyadminMatch1.2
OR
phpmyadminphpmyadminMatch1.2.1
OR
phpmyadminphpmyadminMatch1.2.2
OR
phpmyadminphpmyadminMatch1.2.3
OR
phpmyadminphpmyadminMatch1.2.4
OR
phpmyadminphpmyadminMatch1.2.5
OR
phpmyadminphpmyadminMatch1.2.6
OR
phpmyadminphpmyadminMatch1.2.7
OR
phpmyadminphpmyadminMatch1.2.8
OR
phpmyadminphpmyadminMatch1.2.9
OR
phpmyadminphpmyadminMatch1.2.9.1
OR
phpmyadminphpmyadminMatch1.2.9.2
OR
phpmyadminphpmyadminMatch1.2.9.3
OR
phpmyadminphpmyadminMatch1.2.9.4b
OR
phpmyadminphpmyadminMatch1.2.9.4c
OR
phpmyadminphpmyadminMatch1.2.9.5
OR
phpmyadminphpmyadminMatch1.3
OR
phpmyadminphpmyadminMatch1.3alpha
OR
phpmyadminphpmyadminMatch2.11.0
OR
phpmyadminphpmyadminMatch2.11.1.0
OR
phpmyadminphpmyadminMatch2.11.1.1
OR
phpmyadminphpmyadminMatch2.11.1.2
OR
phpmyadminphpmyadminMatch2.11.2.0
OR
phpmyadminphpmyadminMatch2.11.2.1
OR
phpmyadminphpmyadminMatch2.11.2.2
OR
phpmyadminphpmyadminMatch2.11.3.0
OR
phpmyadminphpmyadminMatch2.11.4.0
OR
phpmyadminphpmyadminMatch2.11.5.0
OR
phpmyadminphpmyadminMatch2.11.5.1
OR
phpmyadminphpmyadminMatch2.11.5.2
OR
phpmyadminphpmyadminMatch2.11.6.0
OR
phpmyadminphpmyadminMatch2.11.7.0
OR
phpmyadminphpmyadminMatch2.11.7.1
OR
phpmyadminphpmyadminMatch2.11.8.0
OR
phpmyadminphpmyadminMatch2.11.9.0
OR
phpmyadminphpmyadminMatch2.11.9.1
OR
phpmyadminphpmyadminMatch2.11.9.2
OR
phpmyadminphpmyadminMatch2.11.9.3
OR
phpmyadminphpmyadminMatch2.11.9.4
OR
phpmyadminphpmyadminMatch2.11.9.5
OR
phpmyadminphpmyadminMatch2.11.9.6
OR
phpmyadminphpmyadminMatch2.11.10.0
OR
phpmyadminphpmyadminMatch2.11.10.1
OR
phpmyadminphpmyadminMatch3.0.0
OR
phpmyadminphpmyadminMatch3.0.0alpha
OR
phpmyadminphpmyadminMatch3.0.0beta
OR
phpmyadminphpmyadminMatch3.0.0rc1
OR
phpmyadminphpmyadminMatch3.0.1
OR
phpmyadminphpmyadminMatch3.0.1rc1
OR
phpmyadminphpmyadminMatch3.0.1.1
OR
phpmyadminphpmyadminMatch3.1.0
OR
phpmyadminphpmyadminMatch3.1.0beta1
OR
phpmyadminphpmyadminMatch3.1.1
OR
phpmyadminphpmyadminMatch3.1.1rc1
OR
phpmyadminphpmyadminMatch3.1.2
OR
phpmyadminphpmyadminMatch3.1.2rc1
OR
phpmyadminphpmyadminMatch3.1.3
OR
phpmyadminphpmyadminMatch3.1.3rc1
OR
phpmyadminphpmyadminMatch3.1.3.1
OR
phpmyadminphpmyadminMatch3.1.3.2
OR
phpmyadminphpmyadminMatch3.1.4
OR
phpmyadminphpmyadminMatch3.1.4rc2
OR
phpmyadminphpmyadminMatch3.1.5
OR
phpmyadminphpmyadminMatch3.1.5rc1
OR
phpmyadminphpmyadminMatch3.2.0
OR
phpmyadminphpmyadminMatch3.2.0beta1
OR
phpmyadminphpmyadminMatch3.2.0rc1
OR
phpmyadminphpmyadminMatch3.2.1
OR
phpmyadminphpmyadminMatch3.2.1rc1
OR
phpmyadminphpmyadminMatch3.2.2
OR
phpmyadminphpmyadminMatch3.2.2rc1
OR
phpmyadminphpmyadminMatch3.3.0.0
OR
phpmyadminphpmyadminMatch3.3.1.0
OR
phpmyadminphpmyadminMatch3.3.2.0
OR
phpmyadminphpmyadminMatch3.3.3.0
OR
phpmyadminphpmyadminMatch3.3.4.0
OR
phpmyadminphpmyadminMatch3.3.5.0
OR
phpmyadminphpmyadminMatch3.3.5.1
OR
phpmyadminphpmyadminMatch3.3.6
OR
phpmyadminphpmyadminMatch3.3.7
OR
phpmyadminphpmyadminMatch3.3.8
OR
phpmyadminphpmyadminMatch3.3.8.1
OR
phpmyadminphpmyadminMatch3.3.9.0
OR
phpmyadminphpmyadminMatch3.3.9.1
OR
phpmyadminphpmyadminMatch3.3.9.2
OR
phpmyadminphpmyadminMatch3.3.10.0
OR
phpmyadminphpmyadminMatch3.4.0.0
OR
phpmyadminphpmyadminMatch3.4.1.0
OR
phpmyadminphpmyadminMatch3.4.2.0
OR
phpmyadminphpmyadminMatch3.4.3.0
OR
phpmyadminphpmyadminMatch3.4.3.1
OR
phpmyadminphpmyadminMatch3.4.3.2
OR
phpmyadminphpmyadminMatch3.4.4.0
OR
phpmyadminphpmyadminMatch3.4.5.0
OR
phpmyadminphpmyadminMatch3.4.6.0
OR
phpmyadminphpmyadminMatch3.4.7.0
OR
phpmyadminphpmyadminMatch3.4.7.1
OR
phpmyadminphpmyadminMatch3.4.8.0
OR
phpmyadminphpmyadminMatch3.4.9.0
OR
phpmyadminphpmyadminMatch3.4.10.0
OR
phpmyadminphpmyadminMatch3.4.10.1
OR
phpmyadminphpmyadminMatch3.4.10.2
OR
phpmyadminphpmyadminMatch3.4.11
OR
phpmyadminphpmyadminMatch3.5.0.0
OR
phpmyadminphpmyadminMatch3.5.1.0
OR
phpmyadminphpmyadminMatch3.5.2.0
OR
phpmyadminphpmyadminMatch3.5.2.1
OR
phpmyadminphpmyadminMatch3.5.2.2
OR
phpmyadminphpmyadminMatch3.5.3.0
OR
phpmyadminphpmyadminMatch3.5.4
OR
phpmyadminphpmyadminMatch3.5.5
OR
phpmyadminphpmyadminMatch3.5.6
OR
phpmyadminphpmyadminMatch3.5.7
OR
phpmyadminphpmyadminMatch3.5.7rc1
OR
phpmyadminphpmyadminMatch3.5.8
OR
phpmyadminphpmyadminMatch3.5.8rc1
OR
phpmyadminphpmyadminMatch3.5.8.1
OR
phpmyadminphpmyadminMatch3.5.8.2
OR
phpmyadminphpmyadminMatch4.0.0
OR
phpmyadminphpmyadminMatch4.0.0rc2
OR
phpmyadminphpmyadminMatch4.0.0rc3
OR
phpmyadminphpmyadminMatch4.0.1
OR
phpmyadminphpmyadminMatch4.0.2
OR
phpmyadminphpmyadminMatch4.0.3
OR
phpmyadminphpmyadminMatch4.0.4
OR
phpmyadminphpmyadminMatch4.0.4.1
OR
phpmyadminphpmyadminMatch4.0.4.2
OR
phpmyadminphpmyadminMatch4.0.5
OR
phpmyadminphpmyadminMatch4.0.6
OR
phpmyadminphpmyadminMatch4.0.7
OR
phpmyadminphpmyadminMatch4.0.8
OR
phpmyadminphpmyadminMatch4.0.9
OR
phpmyadminphpmyadminMatch4.1.0
OR
phpmyadminphpmyadminMatch4.1.1
OR
phpmyadminphpmyadminMatch4.1.2
OR
phpmyadminphpmyadminMatch4.1.3
OR
phpmyadminphpmyadminMatch4.1.4
OR
phpmyadminphpmyadminMatch4.1.5
VendorProductVersionCPE
phpmyadminphpmyadmin3.3.7cpe:/a:phpmyadmin:phpmyadmin:3.3.7:::
phpmyadminphpmyadmin1.2.9.3cpe:/a:phpmyadmin:phpmyadmin:1.2.9.3:::
phpmyadminphpmyadmin1.2.6cpe:/a:phpmyadmin:phpmyadmin:1.2.6:::
phpmyadminphpmyadmin3.2.0cpe:/a:phpmyadmin:phpmyadmin:3.2.0:::
phpmyadminphpmyadmin2.11.2.2cpe:/a:phpmyadmin:phpmyadmin:2.11.2.2:::
phpmyadminphpmyadmin3.3.8.1cpe:/a:phpmyadmin:phpmyadmin:3.3.8.1:::
phpmyadminphpmyadmin4.1.5cpe:/a:phpmyadmin:phpmyadmin:4.1.5:::
phpmyadminphpmyadmin3.4.6.0cpe:/a:phpmyadmin:phpmyadmin:3.4.6.0:::
phpmyadminphpmyadmin1.0.8cpe:/a:phpmyadmin:phpmyadmin:1.0.8:::
phpmyadminphpmyadmin4.0.8cpe:/a:phpmyadmin:phpmyadmin:4.0.8:::
Rows per page:
1-10 of 1501

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5

Confidence

High

EPSS

0.002

Percentile

51.4%