FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2011-4782

This CVE name corresponds to:

Entered Topic
2011-12-22 phpMyAdmin -- Multiple XSS

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2011-4782
Phase Assigned(20111213)

Description

Cross-site scripting (XSS) vulnerability in libraries/config/ConfigFile.class.php in the setup interface in phpMyAdmin 3.4.x before 3.4.9 allows remote attackers to inject arbitrary web script or HTML via the host parameter.

References

Source Reference
CONFIRM http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin;a=commit;h=0e707906e69ce90c4852a0fce2a0fac7db86a3cd
CONFIRM http://www.phpmyadmin.net/home_page/security/PMASA-2011-19.php
FEDORA FEDORA-2011-17369
FEDORA FEDORA-2011-17370
MANDRIVA MDVSA-2011:198
XF phpmyadmin-configfileclass-xss(71938)