phpMyAdmin Tracking Feature Multiple Cross Site Scripting Vulnerabilities
BID:49306
Info
phpMyAdmin Tracking Feature Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 49306 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-3181 CVE-2011-3181 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 24 2011 12:00AM |
| Updated: | Apr 13 2015 08:58PM |
| Credit: | <br>Norman Hippert and The-Wildcat.de |
| Vulnerable: |
phpMyAdmin phpMyAdmin 3.4.3 phpMyAdmin phpMyAdmin 3.3.8 phpMyAdmin phpMyAdmin 3.3.7 phpMyAdmin phpMyAdmin 3.3.6 phpMyAdmin phpMyAdmin 3.3.5 phpMyAdmin phpMyAdmin 3.3.3 0 phpMyAdmin phpMyAdmin 3.4.3.2 phpMyAdmin phpMyAdmin 3.4.3.1 phpMyAdmin phpMyAdmin 3.4.1 phpMyAdmin phpMyAdmin 3.4.0-beta1 phpMyAdmin phpMyAdmin 3.4.0 phpMyAdmin phpMyAdmin 3.3.9.2 phpMyAdmin phpMyAdmin 3.3.8.1 phpMyAdmin phpMyAdmin 3.3.6 phpMyAdmin phpMyAdmin 3.3.5.1 phpMyAdmin phpMyAdmin 3.3.5.0 phpMyAdmin phpMyAdmin 3.3.4.0 phpMyAdmin phpMyAdmin 3.3.2.0 phpMyAdmin phpMyAdmin 3.3.10.3 phpMyAdmin phpMyAdmin 3.3.10.2 phpMyAdmin phpMyAdmin 3.3.10.1 phpMyAdmin phpMyAdmin 3.3.1.0 phpMyAdmin phpMyAdmin 3.3.0.0 phpMyAdmin phpMyAdmin 3.3.0-dev MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
phpMyAdmin phpMyAdmin 3.4.4 phpMyAdmin phpMyAdmin 3.3.10.4 |
Discussion
phpMyAdmin Tracking Feature Multiple Cross Site Scripting Vulnerabilities
phpMyAdmin is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
phpMyAdmin 3.3.0 to 3.4.3.2 are vulnerable.
phpMyAdmin is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
phpMyAdmin 3.3.0 to 3.4.3.2 are vulnerable.
Exploit / POC
phpMyAdmin Tracking Feature Multiple Cross Site Scripting Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim to follow a malicious URI.
To exploit these issues, an attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
phpMyAdmin Tracking Feature Multiple Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva phpmyadmin-3.4.6-0.1mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva phpmyadmin-3.4.6-0.1mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/
References
phpMyAdmin Tracking Feature Multiple Cross Site Scripting Vulnerabilities
References:
References:
- phpMyAdmin Homepage (phpMyAdmin)
- PMASA-2011-13: Multiple XSS in the Tracking feature (phpMyAdmin)