Cross-site scripting (XSS) vulnerability in the micro history implementation in phpMyAdmin 4.0.x before 4.0.10.3, 4.1.x before 4.1.14.4, and 4.2.x before 4.2.8.1 allows remote attackers to inject arbitrary web script or HTML, and consequently conduct a cross-site request forgery (CSRF) attack to create a root account, via a crafted URL, related to js/ajax.js.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 02:14
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-updates/2014-09/msg00032.html - | |
References | () http://www.phpmyadmin.net/home_page/security/PMASA-2014-10.php - Patch, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/69790 - | |
References | () https://github.com/phpmyadmin/phpmyadmin/commit/33b39f9f1dd9a4d27856530e5ac004e23b30e8ac - | |
References | () https://security.gentoo.org/glsa/201505-03 - |
Information
Published : 2014-11-08 11:55
Updated : 2024-11-21 02:14
NVD link : CVE-2014-6300
Mitre link : CVE-2014-6300
CVE.ORG link : CVE-2014-6300
JSON object : View
Products Affected
opensuse
- opensuse
phpmyadmin
- phpmyadmin
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')