phpmyadmin

Page content
  • Author: Miklos Vajna
  • Vulnerable: 3.3.7-1haven1
  • Unaffected: 3.3.8.1-1haven1

A vulnerability has been reported in phpMyAdmin, which can be exploited by malicious people to conduct cross-site scripting attacks. Certain unspecified input passed to the setup script is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user’s browser session in context of an affected site. NOTE: Successful exploitation requires that installation best-practices have not been followed and the setup scripts have not been deleted after a successful installation.

CVEs: