CVE-2012-1190Cross-site Scripting in Phpmyadmin

CWE-79Cross-site Scripting10 documents5 sources
Severity
4.3MEDIUMNVD
EPSS
0.4%
top 37.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 3
Latest updateMay 14

Description

Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication.js in phpMyAdmin 3.4.x before 3.4.10.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted database name.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/phpmyadmin< phpmyadmin 4:3.4.10.1-1 (bookworm)
Debianphpmyadmin/phpmyadmin< 4:3.4.10.1-1+3
NVDphpmyadmin/phpmyadmin15 versions+14

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2xg6-qhwr-gp7p: Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication2022-05-14
OSV
CVE-2012-1190: Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication2012-05-03

📋Vendor Advisories

1
Debian
CVE-2012-1190: phpmyadmin - Cross-site scripting (XSS) vulnerability in the replication-setup functionality ...2012

💬Community

5
Bugzilla
CVE-2012-1457 clamav: overly long length field in tar files evade detection2012-03-22
Bugzilla
CVE-2012-1190 phpMyAdmin: XSS in replication setup (PMASA-2012-1) [epel-6]2012-02-18
Bugzilla
CVE-2012-1190 phpMyAdmin: XSS in replication setup (PMASA-2012-1) [epel-5]2012-02-18
Bugzilla
CVE-2012-1190 phpMyAdmin: XSS in replication setup (PMASA-2012-1)2012-02-18
Bugzilla
CVE-2012-1190 phpMyAdmin: XSS in replication setup (PMASA-2012-1) [fedora-all]2012-02-18