FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2011-3181

This CVE name corresponds to:

Entered Topic
2011-08-24 phpMyAdmin -- multiple XSS vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2011-3181
Phase Assigned(20110819)

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Tracking feature in phpMyAdmin 3.3.x before 3.3.10.4 and 3.4.x before 3.4.4 allow remote attackers to inject arbitrary web script or HTML via a (1) table name, (2) column name, or (3) index name.

References

Source Reference
CONFIRM http://www.phpmyadmin.net/home_page/security/PMASA-2011-13.php
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=733475
DEBIAN DSA-2391
FEDORA FEDORA-2011-11477
FEDORA FEDORA-2011-11594
FEDORA FEDORA-2011-11630
MANDRIVA MDVSA-2011:158
BID 49306
SECUNIA 45709
SECUNIA 45990