CVE-2011-4064Cross-site Scripting in Phpmyadmin

Severity
4.3MEDIUMNVD
EPSS
0.5%
top 33.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 1
Latest updateMay 17

Description

Cross-site scripting (XSS) vulnerability in the setup interface in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/phpmyadmin< phpmyadmin 4:3.4.6-1 (bookworm)
Debianphpmyadmin/phpmyadmin< 4:3.4.6-1+3
NVDphpmyadmin/phpmyadmin8 versions+7

🔴Vulnerability Details

2
GHSA
GHSA-52wv-2qwp-5w9x: Cross-site scripting (XSS) vulnerability in the setup interface in phpMyAdmin 32022-05-17
OSV
CVE-2011-4064: Cross-site scripting (XSS) vulnerability in the setup interface in phpMyAdmin 32011-11-01

📋Vendor Advisories

1
Debian
CVE-2011-4064: phpmyadmin - Cross-site scripting (XSS) vulnerability in the setup interface in phpMyAdmin 3....2011

💬Community

4
Bugzilla
CVE-2011-3646 CVE-2011-4064 phpMyAdmin: multiple flaws corrected in 3.4.6 (PMASA-2011-15, PMASA-2011-16) [epel-5]2011-10-18
Bugzilla
CVE-2011-3646 CVE-2011-4064 phpMyAdmin: multiple flaws corrected in 3.4.6 (PMASA-2011-15, PMASA-2011-16) [fedora-all]2011-10-18
Bugzilla
CVE-2011-3646 CVE-2011-4064 phpMyAdmin: multiple flaws corrected in 3.4.6 (PMASA-2011-15, PMASA-2011-16) [epel-6]2011-10-18
Bugzilla
CVE-2011-3646 CVE-2011-4064 phpMyAdmin: multiple flaws corrected in 3.4.6 (PMASA-2011-15, PMASA-2011-16)2011-10-18