CVE-2014-5273
published 2014-08-22CVE-2014-5273: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.2, 4.1.x before 4.1.14.3, and 4.2.x before 4.2.7.1 allow remote…
PriorityP414low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
1.71%
74.7th percentile
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.2, 4.1.x before 4.1.14.3, and 4.2.x before 4.2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) browse table page, related to js/sql.js; (2) ENUM editor page, related to js/functions.js; (3) monitor page, related to js/server_status_monitor.js; (4) query charts page, related to js/tbl_chart.js; or (5) table relations page, related to libraries/tbl_relation.lib.php.
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | phpmyadmin | < phpmyadmin 4:4.2.7.1-1 (bookworm) | phpmyadmin 4:4.2.7.1-1 (bookworm) |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv3.5LOW
vendor_debian3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qjm2-f85j-5793: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4
ghsa_unreviewed·2022-05-17
CVE-2014-5273 [LOW] CWE-79 GHSA-qjm2-f85j-5793: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.2, 4.1.x before 4.1.14.3, and 4.2.x before 4.2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) browse table page, related to js/sql.js; (2) ENUM editor page, related to js/functions.js; (3) monitor page, related to js/server_status_monitor.js; (4) query charts page, related to js/tbl_chart.js; or (5) table relations page, related to libraries/tbl_relation.lib.php.
OSV
CVE-2014-5273: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4
osv·2014-08-22·CVSS 3.5
CVE-2014-5273 [LOW] CVE-2014-5273: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.2, 4.1.x before 4.1.14.3, and 4.2.x before 4.2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) browse table page, related to js/sql.js; (2) ENUM editor page, related to js/functions.js; (3) monitor page, related to js/server_status_monitor.js; (4) query charts page, related to js/tbl_chart.js; or (5) table relations page, related to libraries/tbl_relation.lib.php.
Debian
CVE-2014-5273: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4...
vendor_debian·2014·CVSS 3.5
CVE-2014-5273 [LOW] CVE-2014-5273: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4...
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.2, 4.1.x before 4.1.14.3, and 4.2.x before 4.2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) browse table page, related to js/sql.js; (2) ENUM editor page, related to js/functions.js; (3) monitor page, related to js/server_status_monitor.js; (4) query charts page, related to js/tbl_chart.js; or (5) table relations page, related to libraries/tbl_relation.lib.php.
Scope: local
bookworm: resolved (fixed in 4:4.2.7.1-1)
bullseye: resolved (fixed in 4:4.2.7.1-1)
forky: resolved (fixed in 4:4.2.7.1-1)
sid: resolved (fixed in 4:4.2.7.1-1)
trixie: resolved (fixed in 4:4.2.7.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-5274 CVE-2014-5273 phpMyAdmin: various flaws [fedora-all]
bugzilla·2014-08-18·CVSS 3.5
CVE-2014-5274 [LOW] CVE-2014-5274 CVE-2014-5273 phpMyAdmin: various flaws [fedora-all]
CVE-2014-5274 CVE-2014-5273 phpMyAdmin: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whi
Bugzilla
CVE-2014-5274 CVE-2014-5273 phpMyAdmin: various flaws [epel-7]
bugzilla·2014-08-18·CVSS 3.5
CVE-2014-5274 [LOW] CVE-2014-5274 CVE-2014-5273 phpMyAdmin: various flaws [epel-7]
CVE-2014-5274 CVE-2014-5273 phpMyAdmin: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for phpMyAdmin: see blocks bug list for full d
Bugzilla
CVE-2014-5273 phpMyAdmin: multiple cross-site scripting issues (PMASA-2014-8)
bugzilla·2014-08-18·CVSS 3.5
CVE-2014-5273 [LOW] CVE-2014-5273 phpMyAdmin: multiple cross-site scripting issues (PMASA-2014-8)
CVE-2014-5273 phpMyAdmin: multiple cross-site scripting issues (PMASA-2014-8)
Multiple cross-site scripting issues were fixed in phpMyAdmin versions 4.0.10.2, 4.1.14.3, and 4.2.7.1. Individual patches are available from the original advisory:
http://www.phpmyadmin.net/home_page/security/PMASA-2014-8.php
Discussion:
Created phpMyAdmin tracking bugs for this issue:
Affects: fedora-all [bug 1130867]
Affects: epel-7 [bug 1130868]
---
I do not know if the older versions in EPEL 5 and 6 are affected
---
http://koji.fedoraproject.org/koji/buildinfo?buildID=566379 for EPEL 6
---
phpMyAdmin-4.2.7.1-1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
---
phpMyAdmin-4.2.7.1-1.fc19 has been pushed to the Fedora 1
http://lists.opensuse.org/opensuse-updates/2014-08/msg00045.htmlhttp://secunia.com/advisories/60397http://www.phpmyadmin.net/home_page/security/PMASA-2014-8.phphttps://github.com/phpmyadmin/phpmyadmin/commit/2c45d7caa614afd71dbe3d0f7270f51ce5569614https://github.com/phpmyadmin/phpmyadmin/commit/3ffc967fb60cf2910cc2f571017e977558c67821https://github.com/phpmyadmin/phpmyadmin/commit/647c9d12e33a6b64e1c3ff7487f72696bdf2dccbhttps://github.com/phpmyadmin/phpmyadmin/commit/90ddeecf60fc029608b972e490b735f3a65ed0cbhttps://github.com/phpmyadmin/phpmyadmin/commit/cd9f302bf7f91a160fe7080f9a612019ef847f1chttp://lists.opensuse.org/opensuse-updates/2014-08/msg00045.htmlhttp://secunia.com/advisories/60397http://www.phpmyadmin.net/home_page/security/PMASA-2014-8.phphttps://github.com/phpmyadmin/phpmyadmin/commit/2c45d7caa614afd71dbe3d0f7270f51ce5569614https://github.com/phpmyadmin/phpmyadmin/commit/3ffc967fb60cf2910cc2f571017e977558c67821https://github.com/phpmyadmin/phpmyadmin/commit/647c9d12e33a6b64e1c3ff7487f72696bdf2dccbhttps://github.com/phpmyadmin/phpmyadmin/commit/90ddeecf60fc029608b972e490b735f3a65ed0cbhttps://github.com/phpmyadmin/phpmyadmin/commit/cd9f302bf7f91a160fe7080f9a612019ef847f1c
2014-08-22
Published