Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-6300
Description:Cross-site scripting (XSS) vulnerability in the micro history implementation in phpMyAdmin 4.0.x before 4.0.10.3, 4.1.x before 4.1.14.4, and 4.2.x before 4.2.8.1 allows remote attackers to inject arbitrary web script or HTML, and consequently conduct a cross-site request forgery (CSRF) attack to create a root account, via a crafted URL, related to js/ajax.js.
Test IDs: 1.3.6.1.4.1.25623.1.0.868203   1.3.6.1.4.1.25623.1.0.112018   1.3.6.1.4.1.25623.1.0.868201   1.3.6.1.4.1.25623.1.0.112019   1.3.6.1.4.1.25623.1.1.10.2014.0383  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-6300
BugTraq ID: 69790
http://www.securityfocus.com/bid/69790
https://security.gentoo.org/glsa/201505-03
SuSE Security Announcement: openSUSE-SU-2014:1150 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-09/msg00032.html




© 1998-2025 E-Soft Inc. All rights reserved.