[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195521

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2011-2642Date: (C)2011-08-01   (M)2023-12-22


Multiple cross-site scripting (XSS) vulnerabilities in the table Print view implementation in tbl_printview.php in phpMyAdmin before 3.3.10.3 and 3.4.x before 3.4.3.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 2.6
Exploit Score: 4.9
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECUNIA-45315
SECUNIA-45365
SECUNIA-45515
BID-48874
DSA-2286
FEDORA-2011-9725
FEDORA-2011-9734
MDVSA-2011:124
http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin%3Ba=commit%3Bh=4bd27166c314faa37cada91533b86377f4d4d214
http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin%3Ba=commit%3Bh=a0823be05aa5835f207c0838b9cca67d2d9a050a
http://www.phpmyadmin.net/home_page/security/PMASA-2011-9.php
https://bugzilla.redhat.com/show_bug.cgi?id=725381
phpmyadmin-table-print-xss(68750)

CPE    74
cpe:/a:phpmyadmin:phpmyadmin:2.11.1.0
cpe:/a:phpmyadmin:phpmyadmin:2.11.5.0
cpe:/a:phpmyadmin:phpmyadmin:2.11.1.1
cpe:/a:phpmyadmin:phpmyadmin:2.11.3.0
...
CWE    1
CWE-79
OVAL    3
oval:org.secpod.oval:def:600595
oval:org.secpod.oval:def:102782
oval:org.secpod.oval:def:102891

© SecPod Technologies