PhpMyAdmin database name Cross-Site Scripting Vulnerability
Release date:
Updated on:
Affected Systems:
PhpMyAdmin 3.x
Unaffected system:
PhpMyAdmin 3.4.10 1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52857
Cve id: CVE-2012-1190
PhpMyAdmin is written in PHP and can be used to control and operate MySQL databases on the web.
PhpMyAdmin has a cross-site scripting vulnerability when processing specially crafted database names. Attackers can exploit this vulnerability to execute arbitrary script code in the user's browser of the affected site to steal Cookie authentication creden.
<* Source: Jakub Galczyk
Link: http://www.phpmyadmin.net/home_page/security/PMASA-2012-1.php
Http://www.bkjia.com/Linux/2012-05/59554htm
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PhpMyAdmin
----------
PhpMyAdmin has released a Security Bulletin (PMASA-2012-1) and corresponding patches for this:
PMASA-2012-1: PMASA-2012-1
Link: http://www.phpmyadmin.net/home_page/security/PMASA-2012-1.php