Description: * With a crafted table name it is possible to trigger an XSS attack in the database search page. * With a crafted SET value or a crafted search query, it is possible to trigger an XSS attacks in the zoom search page. * With a crafted hostname header, it is possible to trigger an XSS attacks in the home page. External References: https://www.phpmyadmin.net/security/PMASA-2016-3/
Created phpMyAdmin tracking bugs for this issue: Affects: fedora-all [bug 1302790] Affects: epel-all [bug 1302791]
phpMyAdmin-4.5.4-1.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
phpMyAdmin-4.5.4.1-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.
phpMyAdmin4-4.0.10.14-1.el5 has been pushed to the Fedora EPEL 5 stable repository. If problems still persist, please make note of it in this bug report.
phpMyAdmin-4.4.15.4-1.el7 has been pushed to the Fedora EPEL 7 stable repository. If problems still persist, please make note of it in this bug report.
phpMyAdmin-4.0.10.14-1.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.