Release date: 2011-12-19
Updated on:
Affected Systems:
PhpMyAdmin 3.5.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 55939
Cve id: CVE-2012-5368
Phpmyadmin is an online management tool for MySQL databases. Its main functions include creating data tables online, running SQL statements, searching and querying data, and importing and exporting data.
PhpMyAdmin 3.5.x has a security vulnerability. It uses JS Code that uses HTTP session to phpmyadmin.net without SSL, and allows man-in-the-middle attackers to execute XSS attacks by modifying this code.
<* Source: vendor
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PhpMyAdmin
----------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.phpmyadmin.net/home_page/security/