Release date:
Updated on:
Affected Systems:
PhpMyAdmin 3.x
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-3181
PhpMyAdmin is written in PHP and can be used to control and operate MySQL databases on the web.
PhpMyAdmin has a security vulnerability in implementation, which can be exploited by malicious users to execute script insertion attacks.
Some inputs passed to tables, columns, and index names are not properly filtered before being used for the Tracking function. You can insert arbitrary HTML and script code to view and execute the code.
<* Source: Norman Hippert
Link: http://www.phpmyadmin.net/home_page/security/PMASA-2011-13.php
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PhpMyAdmin
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.phpmyadmin.net/home_page/security/