Lucene search

K
freebsdFreeBSD3E8B7F8A-49B0-11E4-B711-6805CA0B3D42
HistoryOct 01, 2014 - 12:00 a.m.

phpMyAdmin -- XSS vulnerabilities

2014-10-0100:00:00
vuxml.freebsd.org
16

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.001

Percentile

49.1%

The phpMyAdmin development team reports:

With a crafted ENUM value it is possible to trigger an
XSS in table search and table structure pages. This
vulnerability can be triggered only by someone who is
logged in to phpMyAdmin, as the usual token protection
prevents non-logged-in users from accessing the required
pages.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchphpmyadmin= 4.2.0UNKNOWN
FreeBSDanynoarchphpmyadmin< 4.2.9.1UNKNOWN

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.001

Percentile

49.1%