FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2011-2642

This CVE name corresponds to:

Entered Topic
2011-07-24 phpmyadmin -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2011-2642
Phase Assigned(20110706)

Description

Multiple cross-site scripting (XSS) vulnerabilities in the table Print view implementation in tbl_printview.php in phpMyAdmin before 3.3.10.3 and 3.4.x before 3.4.3.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name.

References

Source Reference
CONFIRM http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin;a=commit;h=4bd27166c314faa37cada91533b86377f4d4d214
CONFIRM http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin;a=commit;h=a0823be05aa5835f207c0838b9cca67d2d9a050a
CONFIRM http://www.phpmyadmin.net/home_page/security/PMASA-2011-9.php
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=725381
DEBIAN DSA-2286
FEDORA FEDORA-2011-9725
FEDORA FEDORA-2011-9734
MANDRIVA MDVSA-2011:124
BID 48874
SECUNIA 45365
SECUNIA 45515
SECUNIA 45315
XF phpmyadmin-table-print-xss(68750)