CVE-2011-3181
published 2011-08-29CVE-2011-3181: Multiple cross-site scripting (XSS) vulnerabilities in the Tracking feature in phpMyAdmin 3.3.x before 3.3.10.4 and 3.4.x before 3.4.4 allow remote attackers…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.33%
81.6th percentile
Multiple cross-site scripting (XSS) vulnerabilities in the Tracking feature in phpMyAdmin 3.3.x before 3.3.10.4 and 3.4.x before 3.4.4 allow remote attackers to inject arbitrary web script or HTML via a (1) table name, (2) column name, or (3) index name.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | phpmyadmin | < phpmyadmin 4:3.4.4-1 (bookworm) | phpmyadmin 4:3.4.4-1 (bookworm) |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q64c-8ph3-645m: Multiple cross-site scripting (XSS) vulnerabilities in the Tracking feature in phpMyAdmin 3
ghsa_unreviewed·2022-05-17
CVE-2011-3181 [MEDIUM] CWE-79 GHSA-q64c-8ph3-645m: Multiple cross-site scripting (XSS) vulnerabilities in the Tracking feature in phpMyAdmin 3
Multiple cross-site scripting (XSS) vulnerabilities in the Tracking feature in phpMyAdmin 3.3.x before 3.3.10.4 and 3.4.x before 3.4.4 allow remote attackers to inject arbitrary web script or HTML via a (1) table name, (2) column name, or (3) index name.
OSV
CVE-2011-3181: Multiple cross-site scripting (XSS) vulnerabilities in the Tracking feature in phpMyAdmin 3
osv·2011-08-29·CVSS 4.3
CVE-2011-3181 [MEDIUM] CVE-2011-3181: Multiple cross-site scripting (XSS) vulnerabilities in the Tracking feature in phpMyAdmin 3
Multiple cross-site scripting (XSS) vulnerabilities in the Tracking feature in phpMyAdmin 3.3.x before 3.3.10.4 and 3.4.x before 3.4.4 allow remote attackers to inject arbitrary web script or HTML via a (1) table name, (2) column name, or (3) index name.
Debian
CVE-2011-3181: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in the Tracking feature in p...
vendor_debian·2011·CVSS 4.3
CVE-2011-3181 [MEDIUM] CVE-2011-3181: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in the Tracking feature in p...
Multiple cross-site scripting (XSS) vulnerabilities in the Tracking feature in phpMyAdmin 3.3.x before 3.3.10.4 and 3.4.x before 3.4.4 allow remote attackers to inject arbitrary web script or HTML via a (1) table name, (2) column name, or (3) index name.
Scope: local
bookworm: resolved (fixed in 4:3.4.4-1)
bullseye: resolved (fixed in 4:3.4.4-1)
forky: resolved (fixed in 4:3.4.4-1)
sid: resolved (fixed in 4:3.4.4-1)
trixie: resolved (fixed in 4:3.4.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-3181 phpMyAdmin XSS flaw
bugzilla·2011-08-25·CVSS 4.3
CVE-2011-3181 [MEDIUM] CVE-2011-3181 phpMyAdmin XSS flaw
CVE-2011-3181 phpMyAdmin XSS flaw
From the upstream advisory:
http://www.phpmyadmin.net/home_page/security/PMASA-2011-13.php
Announcement-ID: PMASA-2011-13
Date: 2011-08-24
Summary:
Multiple XSS in the Tracking feature.
Description:
Missing sanitization on the table, column and index names leads to XSS
vulnerabilities. Severity
We consider this vulnerability to be serious.
Mitigation factor:
An attacker must be logged in via phpMyAdmin to exploit this problem.
Affected Versions
Versions 3.3.0 to 3.4.3.2 are affected.
Solution:
Upgrade to phpMyAdmin 3.3.10.4 or 3.4.4 or apply the related patch listed
below. References
This issue was found by Norman Hippert from The-Wildcat.de.
Assigned CVE ids: CVE-2011-3181
CWE ids: CWE-661 CWE-98
Discussion:
Created phpMyAdmin tracking bugs f
Bugzilla
CVE-2011-3181 phpMyAdmin XSS flaw [epel-5]
bugzilla·2011-08-25·CVSS 4.3
CVE-2011-3181 [MEDIUM] CVE-2011-3181 phpMyAdmin XSS flaw [epel-5]
CVE-2011-3181 phpMyAdmin XSS flaw [epel-5]
epel-5 tracking bug for phpMyAdmin: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
As mentioned in bug #733475 comment #2, I don't think EPEL 5 is affected.
Bugzilla
CVE-2011-3181 phpMyAdmin XSS flaw [epel-6]
bugzilla·2011-08-25·CVSS 4.3
CVE-2011-3181 [MEDIUM] CVE-2011-3181 phpMyAdmin XSS flaw [epel-6]
CVE-2011-3181 phpMyAdmin XSS flaw [epel-6]
epel-6 tracking bug for phpMyAdmin: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
phpMyAdmin-3.4.4-1.fc16 has been submitted as an update for Fedora 16.
https://admin.fedoraproject.org/updates/phpMyAdmin-3.4.4-1.fc16
---
phpMyAdmin-3.4.4-1.fc14 has been submitted as an update for Fedora 14.
https://admin.fedoraproject.org/updates/phpMyAdmin-3.4.4-1.fc14
---
phpMyAdmin-3.4.4-1.el6 has been submitted as an update for Fedora EPEL 6.
https://admin.fedoraproject.org/updates/phpMyAdmin-3.4.4-1.el6
---
Package phpMyAdmin-3.4.4-1.fc16:
* should fix your issue,
* was pushe
Bugzilla
CVE-2011-3181 phpMyAdmin XSS flaw [fedora-all]
bugzilla·2011-08-25·CVSS 4.3
CVE-2011-3181 [MEDIUM] CVE-2011-3181 phpMyAdmin XSS flaw [fedora-all]
CVE-2011-3181 phpMyAdmin XSS flaw [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=733475
Please note: this issue affects multiple supported versions of Fedor
Bugzilla
CVE-2011-3181 phpMyAdmin XSS flaw [epel-4]
bugzilla·2011-08-25·CVSS 4.3
CVE-2011-3181 [MEDIUM] CVE-2011-3181 phpMyAdmin XSS flaw [epel-4]
CVE-2011-3181 phpMyAdmin XSS flaw [epel-4]
epel-4 tracking bug for phpMyAdmin: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
As mentioned in bug #733475 comment #2, I don't think EPEL 4 is affected.
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065824.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-September/065829.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-September/065854.htmlhttp://secunia.com/advisories/45709http://secunia.com/advisories/45990http://www.debian.org/security/2012/dsa-2391http://www.mandriva.com/security/advisories?name=MDVSA-2011:158http://www.phpmyadmin.net/home_page/security/PMASA-2011-13.phphttp://www.securityfocus.com/bid/49306https://bugzilla.redhat.com/show_bug.cgi?id=733475http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065824.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-September/065829.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-September/065854.htmlhttp://secunia.com/advisories/45709http://secunia.com/advisories/45990http://www.debian.org/security/2012/dsa-2391http://www.mandriva.com/security/advisories?name=MDVSA-2011:158http://www.phpmyadmin.net/home_page/security/PMASA-2011-13.phphttp://www.securityfocus.com/bid/49306https://bugzilla.redhat.com/show_bug.cgi?id=733475
2011-08-29
Published