CVE-2011-1940
Published Jan 26, 2012
Last updated a year ago
Overview
- Description
- Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.3.x before 3.3.10.1 and 3.4.x before 3.4.1 allow remote attackers to inject arbitrary web script or HTML via a crafted table name that triggers improper HTML rendering on a Tracking page, related to (1) libraries/tbl_links.inc.php and (2) tbl_tracking.php.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "84100813-C889-4DB0-8D86-E78A047B7C7C" }, { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B99F558E-F696-467D-8C8B-5CFFED2A95D0" }, { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "85BA84E5-8631-478C-8229-CFF36F61569A" }, { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "77430AB8-6EAA-4C99-9700-E5015F8D56FA" }, { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8CFADB43-A63B-4A58-9A9D-232B0CA3F9DC" }, { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "89FC756B-8CF7-4F57-A6AA-8C074F14BCA0" }, { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3EE1361B-D70B-45B9-BD2F-7C049D96928A" }, { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "06EE0CCB-559F-457B-A1EC-79D0680DCDD8" }, { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "00826A60-50A4-4E05-B317-8D0A5FC637BC" }, { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7AC1AECC-6521-4D9D-88D5-86DA8BDB1D26" }, { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.8.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "79093150-F515-42D9-AEF2-86C0C4B1B8AD" }, { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.9.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1FE65F49-CDED-49B0-89F4-CE52E357069A" }, { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.9.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4B29D2E6-F327-4B19-B33F-E888F8B81E7B" }, { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.9.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7C579327-8F92-41AF-926A-86442063A83D" }, { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.10.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8C3F84C4-883B-48DC-9181-E54A87DC973B" }, { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:3.4.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C714361-7AE3-4DC2-994C-7C67B41226B0" } ], "operator": "OR" } ] } ]