phpMyAdmin CVE-2013-4996 Multiple Cross Site Scripting Vulnerabilities
BID:61921
Info
phpMyAdmin CVE-2013-4996 Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 61921 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-4996 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 28 2013 12:00AM |
| Updated: | Jul 14 2014 12:56AM |
| Credit: | Emanuel Bronshtein |
| Vulnerable: |
MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
phpMyAdmin CVE-2013-4996 Multiple Cross Site Scripting Vulnerabilities
phpMyAdmin is prone to multiple cross-site scripting vulnerabilities.
An attacker may leverage these issues to execute arbitrary HTML and script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Note: These issues were previously covered in BID 61493 (phpMyAdmin Multiple SQL Injection and Cross Site Scripting Vulnerabilities) but have been assigned their own record to better document it.
phpMyAdmin 3.5.x prior to 3.5.8.2 and 4.0.x prior to 4.0.4.2 are vulnerable.
phpMyAdmin is prone to multiple cross-site scripting vulnerabilities.
An attacker may leverage these issues to execute arbitrary HTML and script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Note: These issues were previously covered in BID 61493 (phpMyAdmin Multiple SQL Injection and Cross Site Scripting Vulnerabilities) but have been assigned their own record to better document it.
phpMyAdmin 3.5.x prior to 3.5.8.2 and 4.0.x prior to 4.0.4.2 are vulnerable.
Exploit / POC
phpMyAdmin CVE-2013-4996 Multiple Cross Site Scripting Vulnerabilities
An attacker must trick a victim into following a malicious URI to exploit multiple cross-site scripting issues.
An attacker must trick a victim into following a malicious URI to exploit multiple cross-site scripting issues.
Solution / Fix
phpMyAdmin CVE-2013-4996 Multiple Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
phpMyAdmin CVE-2013-4996 Multiple Cross Site Scripting Vulnerabilities
References:
References:
- phpMyAdmin Homepage (phpMyAdmin)