CVE-2011-3592
published 2014-12-26CVE-2011-3592: Multiple cross-site scripting (XSS) vulnerabilities in the PMA_unInlineEditRow function in js/sql.js in phpMyAdmin 3.4.x before 3.4.5 allow remote…
PriorityP413low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
1.45%
70.6th percentile
Multiple cross-site scripting (XSS) vulnerabilities in the PMA_unInlineEditRow function in js/sql.js in phpMyAdmin 3.4.x before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via a (1) database name, (2) table name, or (3) column name that is not properly handled after an inline-editing operation.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | phpmyadmin | < phpmyadmin 4:3.4.5-1 (bookworm) | phpmyadmin 4:3.4.5-1 (bookworm) |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | >= 0 < 4:3.4.5-1 | 4:3.4.5-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:3.4.5-1 | 4:3.4.5-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:3.4.5-1 | 4:3.4.5-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:3.4.5-1 | 4:3.4.5-1 |
| phpmyadmin | phpmyadmin | >= 3.4.0 < 3.4.5 | 3.4.5 |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv3.5LOW
vendor_redhat5.5MEDIUM
vendor_debian3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: bpf: Fix a btf decl_tag bug when tagging a function
vendor_redhat·2025-02-26·CVSS 5.5
CVE-2022-49228 [MEDIUM] kernel: bpf: Fix a btf decl_tag bug when tagging a function
kernel: bpf: Fix a btf decl_tag bug when tagging a function
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix a btf decl_tag bug when tagging a function
syzbot reported a btf decl_tag bug with stack trace below:
general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
CPU: 0 PID: 3592 Comm: syz-executor914 Not tainted 5.16.0-syzkaller-11424-gb7892f7d5cb2 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
RIP: 0010:btf_type_vlen include/linux/btf.h:231 [inline]
RIP: 0010:btf_decl_tag_resolve+0x83e/0xaa0 kernel/bpf/btf.c:3910
...
Call Trace:
btf_resolve+0x251/0x1020 kernel/bpf/btf.c:4198
btf_check_all
Debian
CVE-2011-3592: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in the PMA_unInlineEditRow f...
vendor_debian·2011·CVSS 3.5
CVE-2011-3592 [LOW] CVE-2011-3592: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in the PMA_unInlineEditRow f...
Multiple cross-site scripting (XSS) vulnerabilities in the PMA_unInlineEditRow function in js/sql.js in phpMyAdmin 3.4.x before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via a (1) database name, (2) table name, or (3) column name that is not properly handled after an inline-editing operation.
Scope: local
bookworm: resolved (fixed in 4:3.4.5-1)
bullseye: resolved (fixed in 4:3.4.5-1)
forky: resolved (fixed in 4:3.4.5-1)
sid: resolved (fixed in 4:3.4.5-1)
trixie: resolved (fixed in 4:3.4.5-1)
OSV
phpMyAdmin Multiple XSS Vulnerabilities
osv·2022-05-17
CVE-2011-3592 [LOW] phpMyAdmin Multiple XSS Vulnerabilities
phpMyAdmin Multiple XSS Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in the `PMA_unInlineEditRow` function in js/sql.js in phpMyAdmin 3.4.x before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via a (1) database name, (2) table name, or (3) column name that is not properly handled after an inline-editing operation.
GHSA
phpMyAdmin Multiple XSS Vulnerabilities
ghsa·2022-05-17
CVE-2011-3592 [LOW] CWE-79 phpMyAdmin Multiple XSS Vulnerabilities
phpMyAdmin Multiple XSS Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in the `PMA_unInlineEditRow` function in js/sql.js in phpMyAdmin 3.4.x before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via a (1) database name, (2) table name, or (3) column name that is not properly handled after an inline-editing operation.
OSV
CVE-2011-3592: Multiple cross-site scripting (XSS) vulnerabilities in the PMA_unInlineEditRow function in js/sql
osv·2014-12-26·CVSS 3.5
CVE-2011-3592 [LOW] CVE-2011-3592: Multiple cross-site scripting (XSS) vulnerabilities in the PMA_unInlineEditRow function in js/sql
Multiple cross-site scripting (XSS) vulnerabilities in the PMA_unInlineEditRow function in js/sql.js in phpMyAdmin 3.4.x before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via a (1) database name, (2) table name, or (3) column name that is not properly handled after an inline-editing operation.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2011/09/30/8http://www.phpmyadmin.net/home_page/security/PMASA-2011-14.phphttps://bugzilla.redhat.com/show_bug.cgi?id=738681https://github.com/phpmyadmin/phpmyadmin/commit/2f28ce9c800274190418da0945ce3647d36e1db6http://www.openwall.com/lists/oss-security/2011/09/30/8http://www.phpmyadmin.net/home_page/security/PMASA-2011-14.phphttps://bugzilla.redhat.com/show_bug.cgi?id=738681https://github.com/phpmyadmin/phpmyadmin/commit/2f28ce9c800274190418da0945ce3647d36e1db6
2014-12-26
Published