Korean
<< Back
VID 22538
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The version of phpMyAdmin on the remote host is 3.4.x prior to 3.4.5. This version is affected by multiple cross-site scripting vulnerabilities:

- The data used in the row content display after inline editing is not properly sanitized before it is passed back to the browser.

- The data passed in as table, column, and index names is not properly sanitized before it is passed back to the browser.

A remote attacker may use these issues to cause arbitrary code to be executed in a user's browser, to steal authentication cookies and/or to launch other types of attacks.

* Note: This check solely relied on the version number of the remote phpMyAdmin software to assess this vulnerability, so this might be a false positive.

* References:
http://www.phpmyadmin.net/home_page/security/PMASA-2011-14.php

* Platforms Affected:
phpMyAdmin 3.4.x prior to 3.4.5
Any operating system Any version
Recommendation Upgrade to the latest version of phpMyAdmin (3.4.5 or later), available from the phpMyAdmin Download Web page at http://www.phpmyadmin.net/home_page/downloads.php
Related URL CVE-2011-1940,CVE-2011-1941 (CVE)
Related URL 49648 (SecurityFocus)
Related URL (ISS)