4.3
CVSSv2

CVE-2012-5368

Published: 25/10/2012 Updated: 26/01/2013
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

phpMyAdmin 3.5.x prior to 3.5.3 uses JavaScript code that is obtained through an HTTP session to phpmyadmin.net without SSL, which allows man-in-the-middle malicious users to conduct cross-site scripting (XSS) attacks by modifying this code.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 3.5.0.0

phpmyadmin phpmyadmin 3.5.1.0

phpmyadmin phpmyadmin 3.5.2.0

phpmyadmin phpmyadmin 3.5.2.1

phpmyadmin phpmyadmin 3.5.2.2