diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index b339db95e3b4..7ccccd81a6ee 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -57,6 +57,37 @@ Notes: --> + + phpMyAdmin -- two XSS vulnerabilities due to unescaped table names + + + phpMyAdmin + 4.2.4 + + + + +

The phpMyAdmin development team reports:

+
+

XSS injection due to unescaped db/table name in + navigation hiding.

+
+
+

XSS injection due to unescaped db/table name in + recent/favorite tables.

+
+ +
+ + http://www.phpmyadmin.net/home_page/security/PMASA-2014-2.php + http://www.phpmyadmin.net/home_page/security/PMASA-2014-3.php + + + 2014-06-20 + 2014-06-20 + +
+ iodined -- authentication bypass