CVE-2011-4634Cross-site Scripting in Phpmyadmin

Severity
4.3MEDIUMNVD
EPSS
0.4%
top 37.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 22
Latest updateMay 17

Description

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.8 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted database name, related to the Database Synchronize panel; (2) a crafted database name, related to the Database rename panel; (3) a crafted SQL query, related to the table overview panel; (4) a crafted SQL query, related to the view creation dialog; (5) a crafted column type, related to the table search dialog; or (6) a crafted column

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages4 packages

debiandebian/phpmyadmin< phpmyadmin 4:3.4.8-1 (bookworm)
Packagistphpmyadmin/phpmyadmin3.4.03.4.8
Debianphpmyadmin/phpmyadmin< 4:3.4.8-1+3
NVDphpmyadmin/phpmyadmin10 versions+9

Patches

🔴Vulnerability Details

3
GHSA
phpMyAdmin vulnerable to Cross-site Scripting2022-05-17
OSV
phpMyAdmin vulnerable to Cross-site Scripting2022-05-17
OSV
CVE-2011-4634: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 32011-12-22

📋Vendor Advisories

1
Debian
CVE-2011-4634: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3...2011

💬Community

4
Bugzilla
CVE-2011-4634 phpMyAdmin: multiple XSS flaws (PMASA-2011-18) [epel-5]2011-12-14
Bugzilla
CVE-2011-4634 phpMyAdmin: multiple XSS flaws (PMASA-2011-18) [fedora-all]2011-12-14
Bugzilla
CVE-2011-4634 phpMyAdmin: multiple XSS flaws (PMASA-2011-18)2011-12-14
Bugzilla
CVE-2011-4634 phpMyAdmin: multiple XSS flaws (PMASA-2011-18) [epel-6]2011-12-14