[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250363

 
 

909

 
 

196124

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2391-1 phpmyadmin -- several

ID: oval:org.secpod.oval:def:600709Date: (C)2012-01-30   (M)2024-02-15
Class: PATCHFamily: unix




Several vulnerabilities have been discovered in phpMyAdmin, a tool to administer MySQL over the web. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2011-4107 The XML import plugin allowed a remote attacker to read arbitrary files via XML data containing external entity references. CVE-2011-1940, CVE-2011-3181 Cross site scripting was possible in the table tracking feature, allowing a remote attacker to inject arbitrary web script or HTML. The oldstable distribution is not affected by these problems.

Platform:
Debian 6.0
Product:
phpmyadmin
Reference:
DSA-2391-1
CVE-2011-1940
CVE-2011-3181
CVE-2011-4107
CVE    3
CVE-2011-1940
CVE-2011-3181
CVE-2011-4107
CPE    25
cpe:/o:debian:debian_linux:6.0
cpe:/a:phpmyadmin:phpmyadmin:3.4.0.0
cpe:/a:phpmyadmin:phpmyadmin:3.3.9.1
cpe:/a:phpmyadmin:phpmyadmin:3.3.9.2
...

© SecPod Technologies