Multiple Cross-Site Scripting Vulnerabilities in phpMyAdmin (CVE-2016-2043)
Multiple Cross-Site Scripting Vulnerabilities in phpMyAdmin (CVE-2016-2043)
Release date:
Updated on:
Affected Systems:
PhpMyAdmin 4.5.4> 4.5.x
PhpMyAdmin 4.4.15.3> 4.4.x
Description:
CVE (CAN) ID: CVE-2016-2043
Phpmyadmin is an online management tool for MySQL databases.
The goToFinish1NF function in js/normalization. js has the cross-site scripting vulnerability in phpMyAdmin 4.4.15.3 and later versions 4.4.4.5.x and 4.5.4. Remote attackers can exploit the table name on the normalization page to inject arbitrary Web scripts or HTML.
<* Source: Emanuel Bronshtein
*>
Suggestion:
Vendor patch:
PhpMyAdmin
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.phpmyadmin.net/home_page/security/PMASA-2016-7.php
This article permanently updates the link address: