| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.801660 |
| Category: | Web application abuses |
| Title: | phpMyAdmin 'error.php' Cross Site Scripting Vulnerability |
| Summary: | Check if phpMyAdmin is vulnerable to Cross-Site Scripting |
| Description: | Overview: The host is running phpMyAdmin and is prone to Cross-Site Scripting Vulnerability. Vulnerability Insight: The flaw is caused by input validation errors in the 'error.php' script when processing crafted BBcode tags containing '@' characters, which could allow attackers to inject arbitrary HTML code within the error page and conduct phishing attacks. Impact: Successful exploitation will allow attackers to inject arbitrary HTML code within the error page and conduct phishing attacks. Impact Level: Application Affected Software/OS: phpMyAdmin version 3.3.8.1 and prior. Fix: No solution or patch is available as of 10th December, 2010. Information regarding this issue will be updated once the solution details are available. For updates refer to http://www.phpmyadmin.net/home_page/downloads.php References: http://www.exploit-db.com/exploits/15699/ http://www.vupen.com/english/advisories/2010/3133 |
| Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2010-4480 http://www.exploit-db.com/exploits/15699 Debian Security Information: DSA-2139 (Google Search) http://www.debian.org/security/2010/dsa-2139 http://www.mandriva.com/security/advisories?name=MDVSA-2011:000 BugTraq ID: 45633 http://www.securityfocus.com/bid/45633 http://secunia.com/advisories/42485 http://secunia.com/advisories/42725 http://www.vupen.com/english/advisories/2010/3133 http://www.vupen.com/english/advisories/2011/0001 http://www.vupen.com/english/advisories/2011/0027 |
| Copyright | Copyright (C) 2010 Greenbone Networks GmbH |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|