Cross-site scripting (XSS) vulnerability in libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php in phpMyAdmin 4.0.x prior to 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted object name associated with a TextLinkTransformationPlugin link.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
phpmyadmin phpmyadmin 4.0.0 |
||
phpmyadmin phpmyadmin 4.0.4.1 |
||
phpmyadmin phpmyadmin 4.0.2 |
||
phpmyadmin phpmyadmin 4.0.1 |
||
phpmyadmin phpmyadmin 4.0.3 |
||
phpmyadmin phpmyadmin 4.0.4 |