CVE-2011-3181Cross-site Scripting in Phpmyadmin

Severity
4.3MEDIUMNVD
EPSS
0.6%
top 30.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 29
Latest updateMay 17

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Tracking feature in phpMyAdmin 3.3.x before 3.3.10.4 and 3.4.x before 3.4.4 allow remote attackers to inject arbitrary web script or HTML via a (1) table name, (2) column name, or (3) index name.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/phpmyadmin< phpmyadmin 4:3.4.4-1 (bookworm)
Debianphpmyadmin/phpmyadmin< 4:3.4.4-1+3
NVDphpmyadmin/phpmyadmin24 versions+23

Patches

🔴Vulnerability Details

2
GHSA
GHSA-q64c-8ph3-645m: Multiple cross-site scripting (XSS) vulnerabilities in the Tracking feature in phpMyAdmin 32022-05-17
OSV
CVE-2011-3181: Multiple cross-site scripting (XSS) vulnerabilities in the Tracking feature in phpMyAdmin 32011-08-29

📋Vendor Advisories

1
Debian
CVE-2011-3181: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in the Tracking feature in p...2011

💬Community

5
Bugzilla
CVE-2011-3181 phpMyAdmin XSS flaw2011-08-25
Bugzilla
CVE-2011-3181 phpMyAdmin XSS flaw [epel-5]2011-08-25
Bugzilla
CVE-2011-3181 phpMyAdmin XSS flaw [epel-6]2011-08-25
Bugzilla
CVE-2011-3181 phpMyAdmin XSS flaw [fedora-all]2011-08-25
Bugzilla
CVE-2011-3181 phpMyAdmin XSS flaw [epel-4]2011-08-25