Korean
<< Back
VID 210129
Severity 20
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The version of phpMyAdmin on the remote host is 3.4.x prior to 3.4.11.1 or 3.5.x prior to 3.5.2.2 This version is affected by multiple cross-site scripting vulnerabilities:

- The Database Structure page by creating a table with a crafted name or using the Empty and Drop links of the crafted table name.
- The Table Operations page of a crafted table by using the 'Empty the table (TRUNCATE)' and 'Delete the table (DROP)' links.
- The Triggers page of a database containing tables with a crafted name when opening the 'Add Trigger' popup.
- When creating a trigger for a table with a crafted name with an invalid definition.
- When visualizing GIS data, having a crafted label name.

* Note: This check solely relied on the version number of the remote phpMyAdmin software to assess this vulnerability, so this might be a false positive.

* References:
http://www.phpmyadmin.net/home_page/security/PMASA-2012-4.php

* Platforms Affected:
phpMyAdmin 3.4.x prior to 3.4.11.1
phpMyAdmin 3.5.x prior to 3.5.2.2
Any operating system Any version
Recommendation Upgrade to the latest version of phpMyAdmin (3.4.11.1 or later or 3.5.2.2 or later), available from the phpMyAdmin Download Web page at http://www.phpmyadmin.net/home_page/downloads.php
Related URL CVE-2012-4345 (CVE)
Related URL 55068 (SecurityFocus)
Related URL (ISS)