CVE-2012-4345Cross-site Scripting in Phpmyadmin

CWE-79Cross-site Scripting14 documents5 sources
Severity
3.5LOWNVD
EPSS
0.2%
top 56.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 21
Latest updateMay 17

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Database Structure page in phpMyAdmin 3.4.x before 3.4.11.1 and 3.5.x before 3.5.2.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) a crafted table name during table creation, or a (2) Empty link or (3) Drop link for a crafted table name.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 6.8 | Impact: 2.9

Affected Packages4 packages

debiandebian/phpmyadmin< phpmyadmin 4:3.4.11.1-1 (bookworm)
Packagistphpmyadmin/phpmyadmin3.43.4.11.1+1
Debianphpmyadmin/phpmyadmin< 4:3.4.11.1-1+3
NVDphpmyadmin/phpmyadmin21 versions+20

Patches

🔴Vulnerability Details

6
OSV
phpMyAdmin Multiple Cross-site Scripting Vulnerabilities in the Database Structure page2022-05-17
GHSA
phpMyAdmin Multiple Cross-site Scripting Vulnerabilities in the Database Structure page2022-05-17
GHSA
phpMyAdmin Multiple XSS Vulnerabilities2022-05-17
OSV
phpMyAdmin Multiple XSS Vulnerabilities2022-05-17
OSV
CVE-2012-4579: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 32012-08-21

📋Vendor Advisories

2
Debian
CVE-2012-4345: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in the Database Structure pa...2012
Debian
CVE-2012-4579: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3...2012

💬Community

4
Bugzilla
CVE-2012-4345 CVE-2012-4579 phpMyAdmin: Multiple XSS in Table operations, Database structure, Trigger and Visualize GIS data pages (PMASA-2012-4) [fedora-all]2012-08-22
Bugzilla
CVE-2012-4345 CVE-2012-4579 phpMyAdmin: Multiple XSS in Table operations, Database structure, Trigger and Visualize GIS data pages (PMASA-2012-4) [epel-6]2012-08-22
Bugzilla
CVE-2012-4345 CVE-2012-4579 phpMyAdmin: Multiple XSS in Table operations, Database structure, Trigger and Visualize GIS data pages (PMASA-2012-4) [epel-5]2012-08-22
Bugzilla
CVE-2012-4345 CVE-2012-4579 phpMyAdmin: Multiple XSS in Table operations, Database structure, Trigger and Visualize GIS data pages (PMASA-2012-4)2012-08-17