Lucene search

K
ubuntucveUbuntu.comUB:CVE-2011-3592
HistoryDec 26, 2014 - 12:00 a.m.

CVE-2011-3592

2014-12-2600:00:00
ubuntu.com
ubuntu.com
8

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.001

Percentile

49.5%

Multiple cross-site scripting (XSS) vulnerabilities in the
PMA_unInlineEditRow function in js/sql.js in phpMyAdmin 3.4.x before 3.4.5
allow remote authenticated users to inject arbitrary web script or HTML via
a (1) database name, (2) table name, or (3) column name that is not
properly handled after an inline-editing operation.

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.001

Percentile

49.5%