4.3
CVSSv2

CVE-2014-9219

Published: 08/12/2014 Updated: 08/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x prior to 4.2.13.1 allows remote malicious users to inject arbitrary web script or HTML via the url parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 4.2.13

phpmyadmin phpmyadmin 4.2.10

phpmyadmin phpmyadmin 4.2.7

phpmyadmin phpmyadmin 4.2.7.1

phpmyadmin phpmyadmin 4.2.0

phpmyadmin phpmyadmin 4.2.1

phpmyadmin phpmyadmin 4.2.3

phpmyadmin phpmyadmin 4.2.4

phpmyadmin phpmyadmin 4.2.9

phpmyadmin phpmyadmin 4.2.9.1

phpmyadmin phpmyadmin 4.2.10.1

phpmyadmin phpmyadmin 4.2.2

phpmyadmin phpmyadmin 4.2.8

phpmyadmin phpmyadmin 4.2.8.1

phpmyadmin phpmyadmin 4.2.11

phpmyadmin phpmyadmin 4.2.12

phpmyadmin phpmyadmin 4.2.5

phpmyadmin phpmyadmin 4.2.6

Vendor Advisories

Debian Bug report logs - #774194 phpmyadmin: CVE-2014-9218 CVE-2014-9219 Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 30 Dec 2014 02:21:01 UTC Severity: g ...