4.3
CVSSv2

CVE-2013-4996

Published: 31/07/2013 Updated: 31/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x prior to 3.5.8.2 and 4.0.x prior to 4.0.4.2 allow remote malicious users to inject arbitrary web script or HTML via vectors involving (1) a crafted database name, (2) a crafted user name, (3) a crafted logo URL in the navigation panel, (4) a crafted entry in a certain proxy list, or (5) crafted content in a version.json file.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 3.5.2.2

phpmyadmin phpmyadmin 3.5.7

phpmyadmin phpmyadmin 3.5.8.1

phpmyadmin phpmyadmin 3.5.1.0

phpmyadmin phpmyadmin 3.5.6

phpmyadmin phpmyadmin 3.5.3.0

phpmyadmin phpmyadmin 3.5.2.0

phpmyadmin phpmyadmin 3.5.8

phpmyadmin phpmyadmin 3.5.0.0

phpmyadmin phpmyadmin 3.5.2.1

phpmyadmin phpmyadmin 3.5.5

phpmyadmin phpmyadmin 3.5.4

phpmyadmin phpmyadmin 4.0.1

phpmyadmin phpmyadmin 4.0.0

phpmyadmin phpmyadmin 4.0.3

phpmyadmin phpmyadmin 4.0.2

phpmyadmin phpmyadmin 4.0.4

phpmyadmin phpmyadmin 4.0.4.1

Vendor Advisories

Several vulnerabilities have been discovered in phpMyAdmin, a tool to administer MySQL over the web The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2013-4995 Authenticated users could inject arbitrary web script or HTML via a crafted SQL query CVE-2013-4996 Cross site scripting was possible via ...