Lucene search

K
freebsdFreeBSDA5D4A82A-7153-11E4-88C7-6805CA0B3D42
HistoryNov 20, 2014 - 12:00 a.m.

phpMyAdmin -- XSS and information disclosure vulnerabilities

2014-11-2000:00:00
vuxml.freebsd.org
21

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

0.018 Low

EPSS

Percentile

88.2%

The phpMyAdmin development team reports:

With a crafted database, table or column name it is
possible to trigger an XSS attack in the table browse
page.
With a crafted ENUM value it is possible to trigger
XSS attacks in the table print view and zoom search
pages.
With a crafted value for font size it is possible to
trigger an XSS attack in the home page.

These vulnerabilities can be triggered only by someone
who is logged in to phpMyAdmin, as the usual token
protection prevents non-logged-in users from accessing the
required pages. Moreover, exploitation of the XSS
vulnerability related to the font size requires forgery of
the pma_fontsize cookie.

In the GIS editor feature, a parameter specifying the
geometry type was not correcly validated, opening the door
to a local file inclusion attack.
This vulnerability can be triggered only by someone who
is logged in to phpMyAdmin, as the usual token protection
prevents non-logged-in users from accessing the required
page.

With a crafted file name it is possible to trigger an
XSS in the error reporting page.
This vulnerability can be triggered only by someone who
is logged in to phpMyAdmin, as the usual token protection
prevents non-logged-in users from accessing the required
page.

In the error reporting feature, a parameter specifying
the file was not correctly validated, allowing the
attacker to derive the line count of an arbitrary file
This vulnerability can be triggered only by someone who
is logged in to phpMyAdmin, as the usual token protection
prevents non-logged-in users from accessing the required
page.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchphpmyadmin=ย 4.2.0UNKNOWN
FreeBSDanynoarchphpmyadmin<ย 4.2.12UNKNOWN

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

0.018 Low

EPSS

Percentile

88.2%