3.5
CVSSv2

CVE-2014-5273

Published: 22/08/2014 Updated: 16/10/2014
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x prior to 4.0.10.2, 4.1.x prior to 4.1.14.3, and 4.2.x prior to 4.2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) browse table page, related to js/sql.js; (2) ENUM editor page, related to js/functions.js; (3) monitor page, related to js/server_status_monitor.js; (4) query charts page, related to js/tbl_chart.js; or (5) table relations page, related to libraries/tbl_relation.lib.php.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 4.0.0

phpmyadmin phpmyadmin 4.0.1

phpmyadmin phpmyadmin 4.0.6

phpmyadmin phpmyadmin 4.0.7

phpmyadmin phpmyadmin 4.0.4.1

phpmyadmin phpmyadmin 4.0.4.2

phpmyadmin phpmyadmin 4.0.5

phpmyadmin phpmyadmin 4.0.10

phpmyadmin phpmyadmin 4.0.2

phpmyadmin phpmyadmin 4.0.8

phpmyadmin phpmyadmin 4.0.9

phpmyadmin phpmyadmin 4.0.3

phpmyadmin phpmyadmin 4.0.4

phpmyadmin phpmyadmin 4.0.10.1

phpmyadmin phpmyadmin 4.1.10

phpmyadmin phpmyadmin 4.1.11

phpmyadmin phpmyadmin 4.1.4

phpmyadmin phpmyadmin 4.1.5

phpmyadmin phpmyadmin 4.1.0

phpmyadmin phpmyadmin 4.1.1

phpmyadmin phpmyadmin 4.1.2

phpmyadmin phpmyadmin 4.1.3

phpmyadmin phpmyadmin 4.1.12

phpmyadmin phpmyadmin 4.1.13

phpmyadmin phpmyadmin 4.1.6

phpmyadmin phpmyadmin 4.1.7

phpmyadmin phpmyadmin 4.1.14

phpmyadmin phpmyadmin 4.1.14.1

phpmyadmin phpmyadmin 4.1.8

phpmyadmin phpmyadmin 4.1.9

phpmyadmin phpmyadmin 4.1.14.2

phpmyadmin phpmyadmin 4.2.1

phpmyadmin phpmyadmin 4.2.2

phpmyadmin phpmyadmin 4.2.0

phpmyadmin phpmyadmin 4.2.7

phpmyadmin phpmyadmin 4.2.3

phpmyadmin phpmyadmin 4.2.4

phpmyadmin phpmyadmin 4.2.5

phpmyadmin phpmyadmin 4.2.6

Vendor Advisories

Debian Bug report logs - #758536 phpmyadmin: CVE-2014-5273 CVE-2014-5274 Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 18 Aug 2014 15:48:01 UTC Severi ...