phpmyadmin security problem
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
phpmyadmin (Ubuntu) |
New
|
Undecided
|
Unassigned |
Bug Description
Binary package hint: phpmyadmin
CVE-2010-4329
Cross site scripting was possible in search, that allowed
a remote attacker to inject arbitrary web script or HTML.
CVE-2010-4480
Cross site scripting was possible in errors, that allowed
a remote attacker to inject arbitrary web script or HTML.
CVE-2010-4481
Display of PHP's phpinfo() function was available to world, but only
if this functionality had been enabled (defaults to off). This may
leak some information about the host system.
Description: Ubuntu 10.04.1 LTS
Release: 10.04
phpmyadmin:
Instalado: 4:3.3.2-1
Candidato: 4:3.3.2-1
Tabela de versão:
*** 4:3.3.2-1 0
500 http://
100 /var/lib/
Here an example:
visibility: | private → public |