Korean
<< Back
VID 22601
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The version of phpMyAdmin on the remote host is 4.x prior to 4.0.5. This version is affected by a clickjacking vulnerability:

the phpMyAdmin 3.5.x install hosted on the remote web server is earlier than 4.0.5 and, therefore, contains a flaw where the 'Header.class.php' script
does not properly sanitize input. This could allow attackers to bypass the application's clickjacking protections.

* References:
http://www.phpmyadmin.net/home_page/security/PMASA-2013-10.php

* Platforms Affected:
phpMyAdmin 4.x prior to 4.0.8
Any operating system Any version
Recommendation Upgrade to the latest version of phpMyAdmin (4.0.5 or later), available from the phpMyAdmin Download Web page at
http://www.phpmyadmin.net/home_page/downloads.php
Related URL CVE-2013-5029 (CVE)
Related URL 61804 (SecurityFocus)
Related URL (ISS)