PT-2010-4433 · Php · Phpmyadmin

Aung Khant

·

Publicado

2010-09-08

·

Atualizado

2022-05-17

·

CVE-2010-2958

CVSS v4.0

5.3

Média

VetorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions phpMyAdmin versions 3.x before 3.3.6
Description A cross-site scripting (XSS) issue exists due to the way error messages are handled, allowing remote attackers to inject arbitrary web script or HTML. This is related to PHP backtrace and error messages.
Recommendations For phpMyAdmin versions 3.x before 3.3.6, update to version 3.3.6 or later to resolve the issue. As a temporary workaround, consider disabling error messages or debugging features to minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-2958
GHSA-FRV8-XJCP-HRM2

Produtos afetados

Phpmyadmin