FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-2284

This CVE name corresponds to:

Entered Topic
2009-06-30 phpmyadmin -- XSS vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-2284
Phase Assigned(20090701)

Description

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark.

References

Source Reference
CONFIRM http://www.phpmyadmin.net/home_page/security/PMASA-2009-5.php
FEDORA FEDORA-2009-7329
FEDORA FEDORA-2009-7337
FEDORA FEDORA-2009-7340
MANDRIVA MDVSA-2009:192
SECUNIA 35649
SECUNIA 35715