Total vulnerabilities in the database
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1) a comment for a table name, as exploited through (a) db_operations.php, (2) the db parameter to (b) db_create.php, (3) the newname parameter to db_operations.php, the (4) query_history_latest, (5) query_history_latest_db, and (6) querydisplay_tab parameters to (c) querywindow.php, and (7) the pos parameter to (d) sql.php.
Software | From | Fixed in |
---|---|---|
phpmyadmin / phpmyadmin | 2.9.1_rc2 | 2.9.1_rc2.x |
phpmyadmin / phpmyadmin | 2.9.0.1 | 2.9.0.1.x |
phpmyadmin / phpmyadmin | 2.9.0.2 | 2.9.0.2.x |
phpmyadmin / phpmyadmin | 2.9.0_rc1 | 2.9.0_rc1.x |
phpmyadmin / phpmyadmin | 2.9.0 | 2.9.0.x |
phpmyadmin / phpmyadmin | 2.9.0.3 | 2.9.0.3.x |
phpmyadmin / phpmyadmin | - | 2.9.1.x |
phpmyadmin / phpmyadmin | 2.9.1_rc1 | 2.9.1_rc1.x |
phpmyadmin / phpmyadmin | 2.9.0_beta1 | 2.9.0_beta1.x |
debian / debian_linux | 3.1 | 3.1.x |
debian / debian_linux | 4.0 | 4.0.x |