CVE-2014-4348
published 2014-06-25CVE-2014-4348: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML…
PriorityP414low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
1.52%
71.7th percentile
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name that is improperly handled after presence in (a) the favorite list or (b) recent tables.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | phpmyadmin | < phpmyadmin 4:4.2.5-1 (bookworm) | phpmyadmin 4:4.2.5-1 (bookworm) |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.2.5-1 | 4:4.2.5-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.2.5-1 | 4:4.2.5-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.2.5-1 | 4:4.2.5-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.2.5-1 | 4:4.2.5-1 |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv3.5LOW
vendor_debian3.5LOW
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r43q-435x-vmw7: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4
ghsa_unreviewed·2022-05-17
CVE-2014-4348 [LOW] CWE-79 GHSA-r43q-435x-vmw7: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name that is improperly handled after presence in (a) the favorite list or (b) recent tables.
OSV
CVE-2014-4348: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4
osv·2014-06-25·CVSS 3.5
CVE-2014-4348 [LOW] CVE-2014-4348: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name that is improperly handled after presence in (a) the favorite list or (b) recent tables.
Red Hat
phpMyAdmin: Self-XSS due to unescaped HTML output in recent/favorite tables navigation
vendor_redhat·2014-06-20·CVSS 3.5
CVE-2014-4348 [LOW] CWE-79 phpMyAdmin: Self-XSS due to unescaped HTML output in recent/favorite tables navigation
phpMyAdmin: Self-XSS due to unescaped HTML output in recent/favorite tables navigation
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name that is improperly handled after presence in (a) the favorite list or (b) recent tables.
Statement: Not vulnerable. This issue did not affect the versions of phpMyAdmin as shipped with any Red Hat product.
Debian
CVE-2014-4348: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4...
vendor_debian·2014·CVSS 3.5
CVE-2014-4348 [LOW] CVE-2014-4348: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4...
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name that is improperly handled after presence in (a) the favorite list or (b) recent tables.
Scope: local
bookworm: resolved (fixed in 4:4.2.5-1)
bullseye: resolved (fixed in 4:4.2.5-1)
forky: resolved (fixed in 4:4.2.5-1)
sid: resolved (fixed in 4:4.2.5-1)
trixie: resolved (fixed in 4:4.2.5-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-4349 CVE-2014-4348 phpMyAdmin: various flaws [fedora-all]
bugzilla·2014-07-09·CVSS 3.5
CVE-2014-4349 [LOW] CVE-2014-4349 CVE-2014-4348 phpMyAdmin: various flaws [fedora-all]
CVE-2014-4349 CVE-2014-4348 phpMyAdmin: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2014-4349 CVE-2014-4348 phpMyAdmin: various flaws [epel-6]
bugzilla·2014-07-09·CVSS 3.5
CVE-2014-4349 [LOW] CVE-2014-4349 CVE-2014-4348 phpMyAdmin: various flaws [epel-6]
CVE-2014-4349 CVE-2014-4348 phpMyAdmin: various flaws [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking bug for phpMyAdmin: see bloc
Bugzilla
CVE-2014-4348 phpMyAdmin: Self-XSS due to unescaped HTML output in recent/favorite tables navigation
bugzilla·2014-07-09·CVSS 3.5
CVE-2014-4348 [LOW] CVE-2014-4348 phpMyAdmin: Self-XSS due to unescaped HTML output in recent/favorite tables navigation
CVE-2014-4348 phpMyAdmin: Self-XSS due to unescaped HTML output in recent/favorite tables navigation
The phpMyAdmin project reports:
Summary
Self-XSS due to unescaped HTML output in recent/favorite tables navigation.
Description
When marking a crafted database or table name as favorite or having it in recent tables, it is possible to trigger an XSS.
External references:
http://www.phpmyadmin.net/home_page/security/PMASA-2014-2.php
Discussion:
Created phpMyAdmin tracking bugs for this issue:
Affects: epel-5 [bug 1117602]
---
Created phpMyAdmin tracking bugs for this issue:
Affects: epel-6 [bug 1117603]
---
Created phpMyAdmin tracking bugs for this issue:
Affects: fedora-all [bug 1117604]
---
phpMyAdmin-4.2.6-1.fc20 has been pushed to the Fedora 20 stable repository. If prob
Bugzilla
CVE-2014-4349 CVE-2014-4348 phpMyAdmin: various flaws [epel-5]
bugzilla·2014-07-09·CVSS 3.5
CVE-2014-4349 [LOW] CVE-2014-4349 CVE-2014-4348 phpMyAdmin: various flaws [epel-5]
CVE-2014-4349 CVE-2014-4348 phpMyAdmin: various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for phpMyAdmin: see bloc
http://phpmyadmin.net/home_page/security/PMASA-2014-2.phphttp://www.securityfocus.com/bid/68201https://github.com/phpmyadmin/phpmyadmin/commit/cb7c703c03f656debcea2a16468bd53660fc888ehttps://github.com/phpmyadmin/phpmyadmin/commit/d18a2dd9faad7e0e96df799b59e16ef587afb838http://phpmyadmin.net/home_page/security/PMASA-2014-2.phphttp://www.securityfocus.com/bid/68201https://github.com/phpmyadmin/phpmyadmin/commit/cb7c703c03f656debcea2a16468bd53660fc888ehttps://github.com/phpmyadmin/phpmyadmin/commit/d18a2dd9faad7e0e96df799b59e16ef587afb838
2014-06-25
Published