Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.70509
Category:Mandrake Local Security Checks
Title:Mandriva Security Advisory MDVSA-2011:158 (phpmyadmin)
Summary:NOSUMMARY
Description:Description:
The remote host is missing an update to phpmyadmin
announced via advisory MDVSA-2011:158.

Multiple vulnerabilities has been found and corrected in phpmyadmin:

Missing sanitization on the table, column and index names leads to
XSS vulnerabilities (CVE-2011-3181).

Firstly, if a row contains javascript code, after inline editing this
row and saving, the code is executed. Secondly, missing sanitization
on the db, table and column names leads to XSS vulnerabilities.

When the js_frame parameter of phpmyadmin.css.php is defined as an
array, an error message shows the full path of this file, leading to
possible further attacks (CVE-2011-3646).

Crafted values entered in the setup interface can produce XSS
also,
if the config directory exists and is writeable, the XSS payload can
be saved to this directory (CVE-2011-4064).

This upgrade provides the latest phpmyadmin version (3.4.6) to address
these vulnerabilities.

Affected: Enterprise Server 5.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDVSA-2011:158
http://www.phpmyadmin.net/home_page/security/PMASA-2011-13.php
http://www.phpmyadmin.net/home_page/security/PMASA-2011-14.php
http://www.phpmyadmin.net/home_page/security/PMASA-2011-15.php
http://www.phpmyadmin.net/home_page/security/PMASA-2011-16.php

Risk factor : High

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-3181
BugTraq ID: 49306
http://www.securityfocus.com/bid/49306
Debian Security Information: DSA-2391 (Google Search)
http://www.debian.org/security/2012/dsa-2391
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065854.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065824.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065829.html
http://www.mandriva.com/security/advisories?name=MDVSA-2011:158
http://secunia.com/advisories/45709
http://secunia.com/advisories/45990
Common Vulnerability Exposure (CVE) ID: CVE-2011-3646
http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069235.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069237.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069234.html
http://secunia.com/advisories/46874
Common Vulnerability Exposure (CVE) ID: CVE-2011-4064
BugTraq ID: 50175
http://www.securityfocus.com/bid/50175
http://securitytracker.com/id?1026199
CopyrightCopyright (c) 2012 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.