CVE-2011-4634
published 2011-12-22CVE-2011-4634: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.8 allow remote attackers to inject arbitrary web script or HTML via (1) a…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.21%
80.6th percentile
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.8 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted database name, related to the Database Synchronize panel; (2) a crafted database name, related to the Database rename panel; (3) a crafted SQL query, related to the table overview panel; (4) a crafted SQL query, related to the view creation dialog; (5) a crafted column type, related to the table search dialog; or (6) a crafted column type, related to the create index dialog.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | phpmyadmin | < phpmyadmin 4:3.4.8-1 (bookworm) | phpmyadmin 4:3.4.8-1 (bookworm) |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | >= 0 < 4:3.4.8-1 | 4:3.4.8-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:3.4.8-1 | 4:3.4.8-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:3.4.8-1 | 4:3.4.8-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:3.4.8-1 | 4:3.4.8-1 |
| phpmyadmin | phpmyadmin | >= 3.4.0 < 3.4.8 | 3.4.8 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
phpMyAdmin vulnerable to Cross-site Scripting
ghsa·2022-05-17
CVE-2011-4634 [LOW] CWE-79 phpMyAdmin vulnerable to Cross-site Scripting
phpMyAdmin vulnerable to Cross-site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.8 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted database name, related to the Database Synchronize panel; (2) a crafted database name, related to the Database rename panel; (3) a crafted SQL query, related to the table overview panel; (4) a crafted SQL query, related to the view creation dialog; (5) a crafted column type, related to the table search dialog; or (6) a crafted column type, related to the create index dialog.
OSV
phpMyAdmin vulnerable to Cross-site Scripting
osv·2022-05-17
CVE-2011-4634 [LOW] phpMyAdmin vulnerable to Cross-site Scripting
phpMyAdmin vulnerable to Cross-site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.8 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted database name, related to the Database Synchronize panel; (2) a crafted database name, related to the Database rename panel; (3) a crafted SQL query, related to the table overview panel; (4) a crafted SQL query, related to the view creation dialog; (5) a crafted column type, related to the table search dialog; or (6) a crafted column type, related to the create index dialog.
OSV
CVE-2011-4634: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3
osv·2011-12-22·CVSS 4.3
CVE-2011-4634 [MEDIUM] CVE-2011-4634: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.8 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted database name, related to the Database Synchronize panel; (2) a crafted database name, related to the Database rename panel; (3) a crafted SQL query, related to the table overview panel; (4) a crafted SQL query, related to the view creation dialog; (5) a crafted column type, related to the table search dialog; or (6) a crafted column type, related to the create index dialog.
Debian
CVE-2011-4634: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3...
vendor_debian·2011·CVSS 4.3
CVE-2011-4634 [MEDIUM] CVE-2011-4634: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3...
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.8 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted database name, related to the Database Synchronize panel; (2) a crafted database name, related to the Database rename panel; (3) a crafted SQL query, related to the table overview panel; (4) a crafted SQL query, related to the view creation dialog; (5) a crafted column type, related to the table search dialog; or (6) a crafted column type, related to the create index dialog.
Scope: local
bookworm: resolved (fixed in 4:3.4.8-1)
bullseye: resolved (fixed in 4:3.4.8-1)
forky: resolved (fixed in 4:3.4.8-1)
sid: resolved (fixed in 4:3.4.8-1)
trixie: resolved (fixed in 4:3.4.8-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4634 phpMyAdmin: multiple XSS flaws (PMASA-2011-18) [epel-5]
bugzilla·2011-12-14·CVSS 4.3
CVE-2011-4634 [MEDIUM] CVE-2011-4634 phpMyAdmin: multiple XSS flaws (PMASA-2011-18) [epel-5]
CVE-2011-4634 phpMyAdmin: multiple XSS flaws (PMASA-2011-18) [epel-5]
epel-5 tracking bug for phpMyAdmin3: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
phpMyAdmin3-3.4.8-1.el5 has been submitted as an update for Fedora EPEL 5.
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2011-5165/phpMyAdmin3-3.4.8-1.el5
---
phpMyAdmin3-3.4.8-1.el5 has been pushed to the Fedora EPEL 5 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2011-4634 phpMyAdmin: multiple XSS flaws (PMASA-2011-18) [fedora-all]
bugzilla·2011-12-14·CVSS 4.3
CVE-2011-4634 [MEDIUM] CVE-2011-4634 phpMyAdmin: multiple XSS flaws (PMASA-2011-18) [fedora-all]
CVE-2011-4634 phpMyAdmin: multiple XSS flaws (PMASA-2011-18) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&b
Bugzilla
CVE-2011-4634 phpMyAdmin: multiple XSS flaws (PMASA-2011-18)
bugzilla·2011-12-14·CVSS 4.3
CVE-2011-4634 [MEDIUM] CVE-2011-4634 phpMyAdmin: multiple XSS flaws (PMASA-2011-18)
CVE-2011-4634 phpMyAdmin: multiple XSS flaws (PMASA-2011-18)
phpMyAdmin 3.4.8 was released to correct the following security flaws [1]:
Using crafted database names, it was possible to produce XSS in the Database
Synchronize and Database rename panels. Using an invalid and crafted SQL query,
it was possible to produce XSS when editing a query on a table overview panel
or when using the view creation dialog. Using a crafted column type, it was
possible to produce XSS in the table search and create index dialogs.
Only phpMyAdmin 3.4.x is affected by this vulnerability.
[1] http://www.phpmyadmin.net/home_page/security/PMASA-2011-18.php
Discussion:
Created phpMyAdmin tracking bugs for this issue
Affects: fedora-all [bug 767668]
Affects: epel-6 [bug 767670]
---
Created phpMyAdmin3 trac
Bugzilla
CVE-2011-4634 phpMyAdmin: multiple XSS flaws (PMASA-2011-18) [epel-6]
bugzilla·2011-12-14·CVSS 4.3
CVE-2011-4634 [MEDIUM] CVE-2011-4634 phpMyAdmin: multiple XSS flaws (PMASA-2011-18) [epel-6]
CVE-2011-4634 phpMyAdmin: multiple XSS flaws (PMASA-2011-18) [epel-6]
epel-6 tracking bug for phpMyAdmin: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
phpMyAdmin-3.4.8-1.el6 has been submitted as an update for Fedora EPEL 6.
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2011-5164/phpMyAdmin-3.4.8-1.el6
---
phpMyAdmin-3.4.8-1.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.
http://lists.fedoraproject.org/pipermail/package-announce/2011-December/071040.htmlhttp://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin%3Ba=commitdiff%3Bh=077c10020e349e8c1beb46309098992fde616913http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin%3Ba=commitdiff%3Bh=1490533d91e9d3820e78ca4eac7981886eaea2cbhttp://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin%3Ba=commitdiff%3Bh=b289fe082441dc739939b0ba15dae0d9dc6cee92http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin%3Ba=commitdiff%3Bh=dac8d6ce256333ff45b5f46270304b8657452740http://www.mandriva.com/security/advisories?name=MDVSA-2011:198http://www.phpmyadmin.net/home_page/security/PMASA-2011-18.phphttp://lists.fedoraproject.org/pipermail/package-announce/2011-December/071040.htmlhttp://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin%3Ba=commitdiff%3Bh=077c10020e349e8c1beb46309098992fde616913http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin%3Ba=commitdiff%3Bh=1490533d91e9d3820e78ca4eac7981886eaea2cbhttp://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin%3Ba=commitdiff%3Bh=b289fe082441dc739939b0ba15dae0d9dc6cee92http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin%3Ba=commitdiff%3Bh=dac8d6ce256333ff45b5f46270304b8657452740http://www.mandriva.com/security/advisories?name=MDVSA-2011:198http://www.phpmyadmin.net/home_page/security/PMASA-2011-18.php
2011-12-22
Published