Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-4348
HistoryJun 25, 2014 - 12:00 a.m.

CVE-2014-4348

2014-06-2500:00:00
ubuntu.com
ubuntu.com
18

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.001

Percentile

47.0%

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x
before 4.2.4 allow remote authenticated users to inject arbitrary web
script or HTML via a crafted (1) database name or (2) table name that is
improperly handled after presence in (a) the favorite list or (b) recent
tables.

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.001

Percentile

47.0%