Lucene search

K
freebsdFreeBSDDB1D3340-E83B-11E1-999B-E0CB4E266481
HistoryAug 12, 2012 - 12:00 a.m.

phpMyAdmin -- Multiple XSS in Table operations, Database structure, Trigger and Visualize GIS data pages

2012-08-1200:00:00
vuxml.freebsd.org
16

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.001

Percentile

36.9%

The phpMyAdmin development team reports:

Using a crafted table name, it was possible to produce a
XSS : 1) On the Database Structure page, creating a new
table with a crafted name 2) On the Database Structure page,
using the Empty and Drop links of the crafted table name 3)
On the Table Operations page of a crafted table, using the
β€˜Empty the table (TRUNCATE)’ and β€˜Delete the table (DROP)’
links 4) On the Triggers page of a database containing
tables with a crafted name, when opening the β€˜Add Trigger’
popup 5) When creating a trigger for a table with a crafted
name, with an invalid definition. Having crafted data in a
database table, it was possible to produce a XSS : 6) When
visualizing GIS data, having a crafted label name.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchphpmyadmin<Β 3.5.2.2UNKNOWN

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.001

Percentile

36.9%