Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Editor Blogs > Security

December 27th, 2011, 09:37 GMT · By Eduard Kovacs

BLOG

phpMyAdmin 3.4.9 Closes Two Cross-Site Scripting Vulnerabilities

SHARE:

Adjust text size:

phpMyAdmin interface Enlarge picture - phpMyAdmin interface
The 3.4.9 variant of the popular open source database administration tool, phpMyAdmin, comes with a couple of security fixes which patch up some flaws that could have allowed a cybercriminal to launch cross-site scripting attacks.

According to the release notes, an XSS flaw existed in the setup interface if specially crafted values were entered. Also, by using malicious URL parameters, it was possible to produce XSS on the export panels in the server, database and table sections.

An attack using the XSS in export would be hard to achieve, especially since it would require the user to be logged in. On the other hand, the hole in the setup partly relies on the fact that the config directory exists and is writeable, but the documentation warns customers not to leave it so.

Versions 3.4.x are affected and even though the vulnerabilities are considered to be non-critical, users are advised to upgrade to phpMyAdmin 3.4.9.

phpMyAdmin 3.4.9 is available for download here.

TELL US WHAT YOU THINK:

747 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Microsoft Confirms Windows 7 Vulnerability

Thunderbird 9 Fixes Critical Security Bug

XSS Vulnerabilities Fixed in Fork CMS 3.1.7

Adobe Closes Security Holes with the Release of Reader and Acrobat 9.4.7

Advanced Onion Router 0.3.0.5 Fixes Buffer Overflow and More

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM