Bug 776701 - VUL-0: CVE-2012-4345: phpMyAdmin: multiple XSS in Table operations, Database structure, Trigger and Visualize GIS data pages
VUL-0: CVE-2012-4345: phpMyAdmin: multiple XSS in Table operations, Database ...
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Christian Wittmer
Security Team bot
Depends on:
  Show dependency treegraph
Reported: 2012-08-21 09:49 UTC by Matthias Weckbecker
Modified: 2015-02-18 23:06 UTC (History)
2 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Matthias Weckbecker 2012-08-21 09:49:25 UTC
Multiple XSS flaws have recently been reported in phpMyAdmin [1]. Attackers
could use this to execute arbitrary JavaScript code to e.g. conduct a theft
of cookies.

[1] http://www.phpmyadmin.net/home_page/security/PMASA-2012-4.php
Comment 1 Christian Wittmer 2012-08-21 14:58:16 UTC
update to, ongoing work
Comment 2 Marcus Meissner 2012-08-30 09:28:06 UTC
Comment 3 Swamp Workflow Management 2012-08-30 10:08:59 UTC
openSUSE-SU-2012:1062-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 776698,776701
CVE References: CVE-2012-4219,CVE-2012-4345
Sources used:
openSUSE 12.2 (src):    phpMyAdmin-
openSUSE 12.1 (src):    phpMyAdmin-