Release date:
Updated on:
Affected Systems:
PhpMyAdmin 3.4.x
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Unaffected system:
PhpMyAdmin 3.4.9
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51226
Cve id: CVE-2011-4780
PhpMyAdmin is written in PHP and can be used to control and operate MySQL databases on the web.
PhpMyAdmin has multiple cross-site scripting vulnerabilities in the implementation of libraries/display_export.lib.php, attackers can exploit these vulnerabilities to create XSS on the export panel of servers, databases, and tables. attackers can execute arbitrary script code in the user browsers of the affected sites to steal Cookie authentication creden.
<* Source: Nils juenann
Link: http://www.phpmyadmin.net/home_page/security/PMASA-2011-20.php
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PhpMyAdmin
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.phpmyadmin.net/home_page/security/