PT-2009-3711 · Phpmyadmin · Phpmyadmin

Luisyana

+2

·

Publicado

2009-03-26

·

Atualizado

2009-07-15

·

CVE-2009-1150

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions phpMyAdmin versions 2.11.x through 2.11.9.4 phpMyAdmin versions 3.x through 3.1.3.0
Description The issue allows remote attackers to inject arbitrary web script or HTML via the pma db filename template cookie in the export page, specifically in the display export.lib.php file. This is a case of cross-site scripting (XSS) vulnerabilities.
Recommendations For phpMyAdmin versions 2.11.x through 2.11.9.4, update to version 2.11.9.5 or later. For phpMyAdmin versions 3.x through 3.1.3.0, update to version 3.1.3.1 or later. As a temporary workaround, consider restricting access to the export page or disabling the use of the pma db filename template cookie until a patch is available.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-1150
DSA-1824-1

Produtos afetados

Phpmyadmin