FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2014-4987

This CVE name corresponds to:

Entered Topic
2014-07-18 phpMyAdmin -- multiple XSS vulnerabilities, missing validation

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2014-4987
Phase Assigned(20140716)

Description

server_user_groups.php in phpMyAdmin 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6 allows remote authenticated users to bypass intended access restrictions and read the MySQL user list via a viewUsers request.

References

Source Reference
CONFIRM http://www.phpmyadmin.net/home_page/security/PMASA-2014-7.php
CONFIRM https://github.com/phpmyadmin/phpmyadmin/commit/395265e9937beb21134626c01a21f44b28e712e5
SUSE openSUSE-SU-2014:1069
SECUNIA 60397