CVE-2016-2043
20.02.2016, 01:59
Cross-site scripting (XSS) vulnerability in the goToFinish1NF function in js/normalization.js in phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a table name to the normalization page.
Cross-site Scripting
Vendor | Product | Version |
---|---|---|
opensuse | leap | 42.1 |
opensuse | opensuse | 13.1 |
opensuse | opensuse | 13.2 |
phpmyadmin | phpmyadmin | 4.4.1 |
phpmyadmin | phpmyadmin | 4.4.1.1 |
phpmyadmin | phpmyadmin | 4.4.2 |
phpmyadmin | phpmyadmin | 4.4.3 |
phpmyadmin | phpmyadmin | 4.4.4 |
phpmyadmin | phpmyadmin | 4.4.5 |
phpmyadmin | phpmyadmin | 4.4.6 |
phpmyadmin | phpmyadmin | 4.4.6.1 |
phpmyadmin | phpmyadmin | 4.4.7 |
phpmyadmin | phpmyadmin | 4.4.8 |
phpmyadmin | phpmyadmin | 4.4.9 |
phpmyadmin | phpmyadmin | 4.4.10 |
phpmyadmin | phpmyadmin | 4.4.11 |
phpmyadmin | phpmyadmin | 4.4.12 |
phpmyadmin | phpmyadmin | 4.4.13 |
phpmyadmin | phpmyadmin | 4.4.13.1 |
phpmyadmin | phpmyadmin | 4.4.14.1 |
phpmyadmin | phpmyadmin | 4.4.15 |
phpmyadmin | phpmyadmin | 4.4.15.1 |
phpmyadmin | phpmyadmin | 4.4.15.2 |
phpmyadmin | phpmyadmin | 4.4.15.3 |
phpmyadmin | phpmyadmin | 4.5.0 |
phpmyadmin | phpmyadmin | 4.5.0.1 |
phpmyadmin | phpmyadmin | 4.5.0.2 |
phpmyadmin | phpmyadmin | 4.5.1 |
phpmyadmin | phpmyadmin | 4.5.2 |
phpmyadmin | phpmyadmin | 4.5.3 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
phpmyadmin |
|
References