CVE-2014-4349
published 2014-06-25CVE-2014-4349: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x before 4.1.14.1 and 4.2.x before 4.2.4 allow remote authenticated users to inject…
PriorityP413low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
2.13%
79.9th percentile
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x before 4.1.14.1 and 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name that is improperly handled after a (1) hide or (2) unhide action.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | phpmyadmin | < phpmyadmin 4:4.2.5-1 (bookworm) | phpmyadmin 4:4.2.5-1 (bookworm) |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.2.5-1 | 4:4.2.5-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.2.5-1 | 4:4.2.5-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.2.5-1 | 4:4.2.5-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.2.5-1 | 4:4.2.5-1 |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv3.5LOW
vendor_debian3.5LOW
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-47r4-gvw9-7fw7: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4
ghsa_unreviewed·2022-05-17
CVE-2014-4349 [LOW] CWE-79 GHSA-47r4-gvw9-7fw7: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x before 4.1.14.1 and 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name that is improperly handled after a (1) hide or (2) unhide action.
OSV
CVE-2014-4349: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4
osv·2014-06-25·CVSS 3.5
CVE-2014-4349 [LOW] CVE-2014-4349: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x before 4.1.14.1 and 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name that is improperly handled after a (1) hide or (2) unhide action.
Red Hat
phpMyAdmin: Self-XSS due to unescaped HTML output in navigation items hiding feature
vendor_redhat·2014-06-20·CVSS 3.5
CVE-2014-4349 [LOW] CWE-79 phpMyAdmin: Self-XSS due to unescaped HTML output in navigation items hiding feature
phpMyAdmin: Self-XSS due to unescaped HTML output in navigation items hiding feature
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x before 4.1.14.1 and 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name that is improperly handled after a (1) hide or (2) unhide action.
Statement: Not vulnerable. This issue did not affect the versions of phpMyAdmin as shipped with any Red Hat product.
Debian
CVE-2014-4349: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x before 4...
vendor_debian·2014·CVSS 3.5
CVE-2014-4349 [LOW] CVE-2014-4349: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x before 4...
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x before 4.1.14.1 and 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name that is improperly handled after a (1) hide or (2) unhide action.
Scope: local
bookworm: resolved (fixed in 4:4.2.5-1)
bullseye: resolved (fixed in 4:4.2.5-1)
forky: resolved (fixed in 4:4.2.5-1)
sid: resolved (fixed in 4:4.2.5-1)
trixie: resolved (fixed in 4:4.2.5-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-4349 CVE-2014-4348 phpMyAdmin: various flaws [fedora-all]
bugzilla·2014-07-09·CVSS 3.5
CVE-2014-4349 [LOW] CVE-2014-4349 CVE-2014-4348 phpMyAdmin: various flaws [fedora-all]
CVE-2014-4349 CVE-2014-4348 phpMyAdmin: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2014-4349 CVE-2014-4348 phpMyAdmin: various flaws [epel-6]
bugzilla·2014-07-09·CVSS 3.5
CVE-2014-4349 [LOW] CVE-2014-4349 CVE-2014-4348 phpMyAdmin: various flaws [epel-6]
CVE-2014-4349 CVE-2014-4348 phpMyAdmin: various flaws [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking bug for phpMyAdmin: see bloc
Bugzilla
CVE-2014-4349 CVE-2014-4348 phpMyAdmin: various flaws [epel-5]
bugzilla·2014-07-09·CVSS 3.5
CVE-2014-4349 [LOW] CVE-2014-4349 CVE-2014-4348 phpMyAdmin: various flaws [epel-5]
CVE-2014-4349 CVE-2014-4348 phpMyAdmin: various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for phpMyAdmin: see bloc
Bugzilla
CVE-2014-4349 phpMyAdmin: Self-XSS due to unescaped HTML output in navigation items hiding feature
bugzilla·2014-07-09·CVSS 3.5
CVE-2014-4349 [LOW] CVE-2014-4349 phpMyAdmin: Self-XSS due to unescaped HTML output in navigation items hiding feature
CVE-2014-4349 phpMyAdmin: Self-XSS due to unescaped HTML output in navigation items hiding feature
The phpMyAdmin project reports:
Summary
Self-XSS due to unescaped HTML output in navigation items hiding feature.
Description
When hiding or unhiding a crafted table name in the navigation, it is possible to trigger an XSS.
External references:
http://www.phpmyadmin.net/home_page/security/PMASA-2014-3.php
Discussion:
Created phpMyAdmin tracking bugs for this issue:
Affects: epel-5 [bug 1117602]
---
Created phpMyAdmin tracking bugs for this issue:
Affects: epel-6 [bug 1117603]
---
Created phpMyAdmin tracking bugs for this issue:
Affects: fedora-all [bug 1117604]
---
phpMyAdmin-4.2.6-1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please ma
http://lists.opensuse.org/opensuse-updates/2014-08/msg00045.htmlhttp://phpmyadmin.net/home_page/security/PMASA-2014-3.phphttp://secunia.com/advisories/60397http://www.securityfocus.com/bid/68205https://github.com/phpmyadmin/phpmyadmin/commit/d4f754c937f9e2c0beadff5b2e38215dde1d6a79https://github.com/phpmyadmin/phpmyadmin/commit/daa98d0c7ed24b529dc5df0d5905873acd0b00behttp://lists.opensuse.org/opensuse-updates/2014-08/msg00045.htmlhttp://phpmyadmin.net/home_page/security/PMASA-2014-3.phphttp://secunia.com/advisories/60397http://www.securityfocus.com/bid/68205https://github.com/phpmyadmin/phpmyadmin/commit/d4f754c937f9e2c0beadff5b2e38215dde1d6a79https://github.com/phpmyadmin/phpmyadmin/commit/daa98d0c7ed24b529dc5df0d5905873acd0b00be
2014-06-25
Published