Bug 733475 (CVE-2011-3181) - CVE-2011-3181 phpMyAdmin XSS flaw
Summary: CVE-2011-3181 phpMyAdmin XSS flaw
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2011-3181
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: public=20110824,reported=20110825,sou...
Depends On: 733477 733478 733479 733480
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-08-25 19:07 UTC by Josh Bressers
Modified: 2019-06-08 18:54 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-09-13 21:31:11 UTC


Attachments (Terms of Use)

Description Josh Bressers 2011-08-25 19:07:42 UTC
From the upstream advisory:
http://www.phpmyadmin.net/home_page/security/PMASA-2011-13.php

Announcement-ID: PMASA-2011-13

Date: 2011-08-24
Summary:
Multiple XSS in the Tracking feature.

Description:
Missing sanitization on the table, column and index names leads to XSS
vulnerabilities.  Severity

We consider this vulnerability to be serious.

Mitigation factor:
An attacker must be logged in via phpMyAdmin to exploit this problem.
Affected Versions

Versions 3.3.0 to 3.4.3.2 are affected.

Solution:
Upgrade to phpMyAdmin 3.3.10.4 or 3.4.4 or apply the related patch listed
below.  References

This issue was found by Norman Hippert from The-Wildcat.de.

Assigned CVE ids: CVE-2011-3181

CWE ids: CWE-661 CWE-98

Comment 1 Josh Bressers 2011-08-25 19:13:21 UTC
Created phpMyAdmin tracking bugs for this issue

Affects: fedora-all [bug 733477]
Affects: epel-4 [bug 733478]
Affects: epel-5 [bug 733479]
Affects: epel-6 [bug 733480]

Comment 2 Robert Scheck 2011-08-25 20:19:21 UTC
Josh, you did a lookup mistake, I think. EPEL 4 and 5 are *not* affected,
because they ship phpMyAdmin 2.x, just EPEL 6 and all Fedora releases.


Note You need to log in before you can comment on or make changes to this bug.