Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Debian 3.1: DSA 1207-2 Moderate: phpMyAdmin Remote Cross-Site Scripting

debian
Calendar Grey November 19, 2006
Debian Logo
Addresses security flaws in phpMyAdmin arising from multiple remote vulnerabilities highlighted in Debian's most recent security notice.
Updated package.

Summary


CVE-2005-3621

CRLF injection vulnerability allows remote attackers to conduct
HTTP response splitting attacks.

CVE-2005-3665

Multiple cross-site scripting (XSS) vulnerabilities allow remote
attackers to inject arbitrary web script or HTML via the (1) HTTP_HOST
variable and (2) various scripts in the libraries directory that
handle header generation.

CVE-2006-1678

Multiple cross-site scripting (XSS) vulnerabilities allow remote
attackers to inject arbitrary web script or HTML via scripts in the
themes directory.

CVE-2006-2418

A cross-site scripting (XSS) vulnerability allows remote attackers
to inject arbitrary web script or HTML via the db parameter of
footer.inc.php.

CVE-2006-5116

A remote attacker could overwrite internal variables through the
_FILES global variable.

For the stable distribution (sarge) these problems have been fixed in
version 2.6.2-3sarge3.

For the upcoming stable release (etch) and unstable dist...

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here