phpMyAdmin Tracking Page HTML Injection Vulnerability
BID:47945
Info
phpMyAdmin Tracking Page HTML Injection Vulnerability
| Bugtraq ID: | 47945 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2011 12:00AM |
| Updated: | May 07 2015 05:14PM |
| Credit: | dave b |
| Vulnerable: |
Typo3 phpMyAdmin 4.10.3 Typo3 phpMyAdmin 4.9 Typo3 phpMyAdmin 4.8.1 Typo3 phpMyAdmin 4.5 phpMyAdmin phpMyAdmin 3.3.8 phpMyAdmin phpMyAdmin 3.3.7 phpMyAdmin phpMyAdmin 3.3.6 phpMyAdmin phpMyAdmin 3.3.5 phpMyAdmin phpMyAdmin 3.3.3 0 phpMyAdmin phpMyAdmin 3.4.0 phpMyAdmin phpMyAdmin 3.3.9.2 phpMyAdmin phpMyAdmin 3.3.8.1 phpMyAdmin phpMyAdmin 3.3.6 phpMyAdmin phpMyAdmin 3.3.5.1 phpMyAdmin phpMyAdmin 3.3.5.0 phpMyAdmin phpMyAdmin 3.3.4.0 phpMyAdmin phpMyAdmin 3.3.2.0 phpMyAdmin phpMyAdmin 3.3.1.0 |
| Not Vulnerable: |
Typo3 phpMyAdmin 4.11 phpMyAdmin phpMyAdmin 3.4.1 phpMyAdmin phpMyAdmin 3.3.10.1 |
Discussion
phpMyAdmin Tracking Page HTML Injection Vulnerability
phpMyAdmin is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
phpMyAdmin versions 3.3.x and 3.4.0 are affected.
phpMyAdmin is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
phpMyAdmin versions 3.3.x and 3.4.0 are affected.
Exploit / POC
phpMyAdmin Tracking Page HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
phpMyAdmin Tracking Page HTML Injection Vulnerability
Solution:
Vendor updates are available. Please see the references for details.
Solution:
Vendor updates are available. Please see the references for details.
References
phpMyAdmin Tracking Page HTML Injection Vulnerability
References:
References:
- phpMyAdmin Homepage (phpMyAdmin)
- TYPO3 Security Bulletin TYPO3-SA-2011-005 (Typo3)
- PMASA-2011-3 (phpMyAdmin)