Lucene search

K
freebsdFreeBSD6B97436C-CE1E-11E2-9CB2-6805CA0B3D42
HistoryJun 05, 2013 - 12:00 a.m.

phpMyAdmin -- XSS due to unescaped HTML output in Create View page

2013-06-0500:00:00
vuxml.freebsd.org
18

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.001

Percentile

30.2%

The phpMyAdmin development team reports:

When creating a view with a crafted name and an incorrect
CREATE statement, it is possible to trigger an XSS.
This vulnerability can be triggered only by someone who
logged in to phpMyAdmin, as the usual token protection
prevents non-logged-in users from accessing the required
form.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchphpmyadmin= 4.0UNKNOWN
FreeBSDanynoarchphpmyadmin< 4.0.3UNKNOWN

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.001

Percentile

30.2%

Related for 6B97436C-CE1E-11E2-9CB2-6805CA0B3D42