Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2014.0310
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2014-0310)
Resumen:The remote host is missing an update for the 'phpmyadmin' package(s) announced via the MGASA-2014-0310 advisory.
Descripción:Summary:
The remote host is missing an update for the 'phpmyadmin' package(s) announced via the MGASA-2014-0310 advisory.

Vulnerability Insight:
In phpMyAdmin before 4.1.14.2, when navigating into the database triggers
page, it is possible to trigger an XSS with a crafted trigger name
(CVE-2014-4955).

In phpMyAdmin before 4.1.14.2, with a crafted column name it is possible to
trigger an XSS when dropping the column in table structure page. With a
crafted table name it is possible to trigger an XSS when dropping or
truncating the table in table operations page (CVE-2014-4986).

In phpMyAdmin before 4.1.14.2, An unpriviledged user could view the MySQL
user list and manipulate the tabs displayed in phpMyAdmin for them
(CVE-2014-4987).

Affected Software/OS:
'phpmyadmin' package(s) on Mageia 3, Mageia 4.

Solution:
Please install the updated package(s).

CVSS Score:
4.0

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:N/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2014-4955
BugTraq ID: 68799
http://www.securityfocus.com/bid/68799
http://secunia.com/advisories/60397
SuSE Security Announcement: openSUSE-SU-2014:1069 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-08/msg00045.html
Common Vulnerability Exposure (CVE) ID: CVE-2014-4986
BugTraq ID: 68803
http://www.securityfocus.com/bid/68803
https://security.gentoo.org/glsa/201505-03
Common Vulnerability Exposure (CVE) ID: CVE-2014-4987
BugTraq ID: 68804
http://www.securityfocus.com/bid/68804
CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.