Korean
<< Back
VID 22615
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The version of phpMyAdmin on the remote host is 3.x prior to 3.3.1. This version is affected by a a cross-site scripting vulnerability. because the 'import.php' script does not properly sanitize the filenames of imported files.

* Note: This check solely relied on the version number of the remote phpMyAdmin software to assess this vulnerability, so this might be a false positive.

* References:
http://www.phpmyadmin.net/home_page/security/PMASA-2014-1.php
https://github.com/phpmyadmin/phpmyadmin/commit/968d5d5f486820bfa30af046f063b9f23304e14a

* Platforms Affected:
phpMyAdmin 3.x prior to 3.3.1
Any operating system Any version
Recommendation Upgrade to the latest version of phpMyAdmin (3.3.1 or later), available from the phpMyAdmin Download Web page at
http://www.phpmyadmin.net/home_page/downloads.php
Related URL CVE-2014-1879 (CVE)
Related URL 65717 (SecurityFocus)
Related URL (ISS)