(CVE-2005-3787): PHPMyAdmin Multiple Cross-Site Scripting Vulnerabilities

Related Vulnerabilities: CVE-2005-3787  

Debian Bug report logs - #360726
(CVE-2005-3787): PHPMyAdmin Multiple Cross-Site Scripting Vulnerabilities

version graph

Reported by: Stephen Gran <sgran@debian.org>

Date: Tue, 4 Apr 2006 11:48:01 UTC

Severity: important

Tags: sarge, security

Found in version phpmyadmin/4:2.6.2-3sarge1

Fixed in versions 4:2.6.4-pl1-1, 4:2.6.2-3sarge1

Done: Thijs Kinkhorst <thijs@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Piotr Roszatycki <dexter@debian.org>:
Bug#360726; Package phpmyadmin. (full text, mbox, link).


Acknowledgement sent to Stephen Gran <sgran@debian.org>:
New Bug report received and forwarded. Copy sent to Piotr Roszatycki <dexter@debian.org>. (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Stephen Gran <sgran@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: (CVE-2005-3787): PHPMyAdmin Multiple Cross-Site Scripting Vulnerabilities
Date: Tue, 4 Apr 2006 12:32:17 +0100
[Message part 1 (text/plain, inline)]
Package: phpmyadmin
Version: 4:2.6.2-3sarge1
Severity: important
Tags: security

http://www.securityfocus.com/bid/16389

phpMyAdmin is prone to multiple cross-site scripting vulnerabilities.
These issues are due to a failure in the application to properly
sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code
executed in the browser of an unsuspecting user in the context of the
affected site. This may facilitate the theft of cookie-based
authentication credentials as well as other attacks.

This is CVE-2005-3787 (I see several other XSS fixes, but not this one;
if this is a duplicate, I am sorry for wasting time).

-- System Information:
Debian Release: 3.1
Architecture: i386 (i686)
Kernel: Linux 2.6.8-3-686-smp
Locale: LANG=en_US.ISO-8859-1, LC_CTYPE=en_US.ISO-8859-1 (charmap=ISO-8859-1) (ignored: LC_ALL set to en_US.ISO-8859-1)

Versions of packages phpmyadmin depends on:
ii  apache-ssl [httpd]        1.3.33-6sarge1 versatile, high-performance HTTP s
ii  debconf                   1.4.30.13      Debian configuration management sy
ii  php4                      4:4.3.10-16    server-side, HTML-embedded scripti
ii  php4-mysql                4:4.3.10-16    MySQL module for php4
ii  wwwconfig-common          0.0.43         Debian web auto configuration

-- 
 -----------------------------------------------------------------
|   ,''`.                                            Stephen Gran |
|  : :' :                                        sgran@debian.org |
|  `. `'                        Debian user, admin, and developer |
|    `-                                     http://www.debian.org |
 -----------------------------------------------------------------
[signature.asc (application/pgp-signature, inline)]

Tags added: sarge Request was from Piotr Roszatycki <dexter@n1.pl> to control@bugs.debian.org. (full text, mbox, link).


Bug marked as fixed in version 4:2.6.4-pl1-1, send any further explanations to Stephen Gran <sgran@debian.org> Request was from Thijs Kinkhorst <thijs@debian.org> to control@bugs.debian.org. (full text, mbox, link).


Bug marked as fixed in version 4:2.6.2-3sarge1, send any further explanations to Stephen Gran <sgran@debian.org> Request was from Thijs Kinkhorst <thijs@debian.org> to control@bugs.debian.org. (full text, mbox, link).


Bug marked as fixed in version 4:2.6.2-3sarge1, send any further explanations to Stephen Gran <sgran@debian.org> Request was from Thijs Kinkhorst <thijs@debian.org> to control@bugs.debian.org. (full text, mbox, link).


Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sun, 24 Jun 2007 23:51:06 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 15:48:58 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.