Release date:
Updated on:
Affected Systems:
PhpMyAdmin 3.4.x
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Description:
--------------------------------------------------------------------------------
Bugtraq id: 55068
Cve id: CVE-2012-4345
PhpMyAdmin is written in PHP and can be used to control and operate MySQL databases on the web.
Multiple HTML injection vulnerabilities exist in phpMyAdmin versions earlier than 3.4.11.1 and earlier than 3.5.2.2. Attackers can exploit these vulnerabilities to inject HTML and JS Code to affected sites, this results in the theft of authentication creden。 and control of the site appearance.
<* Source: Emanuel Bronshtein
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PhpMyAdmin
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.phpmyadmin.net/home_page/security/