PhpMyAdmin libraries/rte/rte_list.lib.php Multiple Cross-Site Scripting Vulnerabilities
Release date:
Updated on:
Affected Systems:
PhpMyAdmin 4.2.x
PhpMyAdmin 4.1.x
PhpMyAdmin 4.0.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-4955
Phpmyadmin is an online management tool for MySQL databases. Its main functions include creating data tables online, running SQL statements, searching and querying data, and importing and exporting data.
In phpMyAdmin 4.0.x, 4.1.x, and 4.2.x, the libraries/rte/rte_list.lib.php PMA_TRI_getRowForList function has multiple cross-site scripting vulnerabilities. authenticated remote users use specially crafted trigger names, attackers can exploit this vulnerability to inject arbitrary Web scripts or HTML.
<* Source: Chirayu Chiripal
Link: http://www.phpmyadmin.net/home_page/security/PMASA-2014-7.php
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PhpMyAdmin
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.phpmyadmin.net/home_page/security/PMASA-2014-5.php
Install the LAMP \ Vsftpd \ Webmin \ phpMyAdmin service and settings in Ubuntu 13.04
Example of LAMP architecture collaborative application-phpMyAdmin
PhpMyAdmin and Wordpress for LAMP applications
PhpMyAdmin logon timeout Solution
Install phpMyAdmin and Adminer in Ubuntu
Implement SSL functions based on LAMP and install phpMyAdmin
PhpMyAdmin details: click here
PhpMyAdmin: click here
This article permanently updates the link address: