CVE-2011-3598

Multiple cross-site scripting (XSS) vulnerabilities in phpPgAdmin before 5.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) a web page title, related to classes/Misc.php; or the (2) return_url or (3) return_desc parameter to display.php.
References
Link Resource
http://freshmeat.net/projects/phppgadmin/releases/336969
http://lists.fedoraproject.org/pipermail/package-announce/2011-October/067843.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-October/067846.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-October/068009.html
http://lists.opensuse.org/opensuse-updates/2012-04/msg00033.html
http://osvdb.org/75997
http://osvdb.org/75998
http://secunia.com/advisories/46248 Vendor Advisory
http://secunia.com/advisories/46426
http://sourceforge.net/mailarchive/forum.php?thread_name=4E897F6C.90905%40free.fr&forum_name=phppgadmin-news Patch
http://www.openwall.com/lists/oss-security/2011/10/04/1 Patch
http://www.openwall.com/lists/oss-security/2011/10/04/10 Patch
http://www.securityfocus.com/bid/49914
https://bugs.gentoo.org/show_bug.cgi?id=385505
https://bugzilla.redhat.com/show_bug.cgi?id=743205 Patch
https://github.com/phppgadmin/phppgadmin/commit/1df248203de055f97e092b50b1dd9643ccb73842 Patch
http://freshmeat.net/projects/phppgadmin/releases/336969
http://lists.fedoraproject.org/pipermail/package-announce/2011-October/067843.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-October/067846.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-October/068009.html
http://lists.opensuse.org/opensuse-updates/2012-04/msg00033.html
http://osvdb.org/75997
http://osvdb.org/75998
http://secunia.com/advisories/46248 Vendor Advisory
http://secunia.com/advisories/46426
http://sourceforge.net/mailarchive/forum.php?thread_name=4E897F6C.90905%40free.fr&forum_name=phppgadmin-news Patch
http://www.openwall.com/lists/oss-security/2011/10/04/1 Patch
http://www.openwall.com/lists/oss-security/2011/10/04/10 Patch
http://www.securityfocus.com/bid/49914
https://bugs.gentoo.org/show_bug.cgi?id=385505
https://bugzilla.redhat.com/show_bug.cgi?id=743205 Patch
https://github.com/phppgadmin/phppgadmin/commit/1df248203de055f97e092b50b1dd9643ccb73842 Patch
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:phppgadmin:phppgadmin:*:*:*:*:*:*:*:*
cpe:2.3:a:phppgadmin:phppgadmin:2.2:*:*:*:*:*:*:*
cpe:2.3:a:phppgadmin:phppgadmin:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:phppgadmin:phppgadmin:3.1:*:*:*:*:*:*:*
cpe:2.3:a:phppgadmin:phppgadmin:3.2:*:*:*:*:*:*:*
cpe:2.3:a:phppgadmin:phppgadmin:3.3:*:*:*:*:*:*:*
cpe:2.3:a:phppgadmin:phppgadmin:3.4:*:*:*:*:*:*:*
cpe:2.3:a:phppgadmin:phppgadmin:3.4.1:*:*:*:*:*:*:*
cpe:2.3:a:phppgadmin:phppgadmin:3.5:*:*:*:*:*:*:*
cpe:2.3:a:phppgadmin:phppgadmin:3.5.2:*:*:*:*:*:*:*
cpe:2.3:a:phppgadmin:phppgadmin:3.5.3:*:*:*:*:*:*:*
cpe:2.3:a:phppgadmin:phppgadmin:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:phppgadmin:phppgadmin:4.2.1:*:*:*:*:*:*:*
cpe:2.3:a:phppgadmin:phppgadmin:4.2.2:*:*:*:*:*:*:*
cpe:2.3:a:phppgadmin:phppgadmin:4.2.3:*:*:*:*:*:*:*
cpe:2.3:a:phppgadmin:phppgadmin:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:phppgadmin:phppgadmin:5.0.1:*:*:*:*:*:*:*

History

21 Nov 2024, 01:30

Type Values Removed Values Added
References () http://freshmeat.net/projects/phppgadmin/releases/336969 - () http://freshmeat.net/projects/phppgadmin/releases/336969 -
References () http://lists.fedoraproject.org/pipermail/package-announce/2011-October/067843.html - () http://lists.fedoraproject.org/pipermail/package-announce/2011-October/067843.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2011-October/067846.html - () http://lists.fedoraproject.org/pipermail/package-announce/2011-October/067846.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2011-October/068009.html - () http://lists.fedoraproject.org/pipermail/package-announce/2011-October/068009.html -
References () http://lists.opensuse.org/opensuse-updates/2012-04/msg00033.html - () http://lists.opensuse.org/opensuse-updates/2012-04/msg00033.html -
References () http://osvdb.org/75997 - () http://osvdb.org/75997 -
References () http://osvdb.org/75998 - () http://osvdb.org/75998 -
References () http://secunia.com/advisories/46248 - Vendor Advisory () http://secunia.com/advisories/46248 - Vendor Advisory
References () http://secunia.com/advisories/46426 - () http://secunia.com/advisories/46426 -
References () http://sourceforge.net/mailarchive/forum.php?thread_name=4E897F6C.90905%40free.fr&forum_name=phppgadmin-news - Patch () http://sourceforge.net/mailarchive/forum.php?thread_name=4E897F6C.90905%40free.fr&forum_name=phppgadmin-news - Patch
References () http://www.openwall.com/lists/oss-security/2011/10/04/1 - Patch () http://www.openwall.com/lists/oss-security/2011/10/04/1 - Patch
References () http://www.openwall.com/lists/oss-security/2011/10/04/10 - Patch () http://www.openwall.com/lists/oss-security/2011/10/04/10 - Patch
References () http://www.securityfocus.com/bid/49914 - () http://www.securityfocus.com/bid/49914 -
References () https://bugs.gentoo.org/show_bug.cgi?id=385505 - () https://bugs.gentoo.org/show_bug.cgi?id=385505 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=743205 - Patch () https://bugzilla.redhat.com/show_bug.cgi?id=743205 - Patch
References () https://github.com/phppgadmin/phppgadmin/commit/1df248203de055f97e092b50b1dd9643ccb73842 - Patch () https://github.com/phppgadmin/phppgadmin/commit/1df248203de055f97e092b50b1dd9643ccb73842 - Patch

Information

Published : 2011-10-08 02:52

Updated : 2024-11-21 01:30


NVD link : CVE-2011-3598

Mitre link : CVE-2011-3598

CVE.ORG link : CVE-2011-3598


JSON object : View

Products Affected

phppgadmin

  • phppgadmin
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')