[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244625

 
 

909

 
 

193379

 
 

277

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-3056Date: (C)2010-08-24   (M)2023-12-22


Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.11.x before 2.11.10.1 and 3.x before 3.3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) db_search.php, (2) db_sql.php, (3) db_structure.php, (4) js/messages.php, (5) libraries/common.lib.php, (6) libraries/database_interface.lib.php, (7) libraries/dbi/mysql.dbi.lib.php, (8) libraries/dbi/mysqli.dbi.lib.php, (9) libraries/db_info.inc.php, (10) libraries/sanitizing.lib.php, (11) libraries/sqlparser.lib.php, (12) server_databases.php, (13) server_privileges.php, (14) setup/config.php, (15) sql.php, (16) tbl_replace.php, and (17) tbl_sql.php.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECUNIA-41000
SECUNIA-41185
BID-42584
ADV-2010-2223
ADV-2010-2231
DSA-2097
FEDORA-2010-13249
FEDORA-2010-13258
MDVSA-2010:163
MDVSA-2010:164
http://www.phpmyadmin.net/home_page/security/PMASA-2010-5.php
http://yehg.net/lab/pr0js/advisories/phpmyadmin/%5Bphpmyadmin-3.3.5%5D_cross_site_scripting%28XSS%29
https://bugzilla.redhat.com/show_bug.cgi?id=625877

CPE    58
cpe:/a:phpmyadmin:phpmyadmin:2.11.1.0
cpe:/a:phpmyadmin:phpmyadmin:2.11.5.0
cpe:/a:phpmyadmin:phpmyadmin:2.11.1.1
cpe:/a:phpmyadmin:phpmyadmin:2.11.3.0
...
CWE    1
CWE-79
OVAL    5
oval:org.secpod.oval:def:100082
oval:org.secpod.oval:def:100129
oval:org.secpod.oval:def:100510
oval:org.secpod.oval:def:600122
...

© SecPod Technologies