ALT-PU-2014-2385-1
Package phpMyAdmin updated to version 4.2.12-alt1 for branch sisyphus in task 135395.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2014-8958
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.6, 4.1.x before 4.1.14.7, and 4.2.x before 4.2.12 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database, (2) table, or (3) column name that is improperly handled during rendering of the table browse page; a crafted ENUM value that is improperly handled during rendering of the (4) table print view or (5) zoom search page; or (6) a crafted pma_fontsize cookie that is improperly handled during rendering of the home page.
- openSUSE-SU-2014:1561
- openSUSE-SU-2014:1561
- DSA-3382
- DSA-3382
- MDVSA-2014:228
- MDVSA-2014:228
- http://www.phpmyadmin.net/home_page/security/PMASA-2014-13.php
- http://www.phpmyadmin.net/home_page/security/PMASA-2014-13.php
- 71243
- 71243
- https://github.com/phpmyadmin/phpmyadmin/commit/1bc04ec95038f2356ad33752090001bf1c047208
- https://github.com/phpmyadmin/phpmyadmin/commit/1bc04ec95038f2356ad33752090001bf1c047208
- https://github.com/phpmyadmin/phpmyadmin/commit/2a3b7393d1d5a8ba0543699df94a08a0f5728fe0
- https://github.com/phpmyadmin/phpmyadmin/commit/2a3b7393d1d5a8ba0543699df94a08a0f5728fe0
- https://github.com/phpmyadmin/phpmyadmin/commit/2ffdbf2d7daa0b92541d8b754e2afac555d3ed21
- https://github.com/phpmyadmin/phpmyadmin/commit/2ffdbf2d7daa0b92541d8b754e2afac555d3ed21
- https://github.com/phpmyadmin/phpmyadmin/commit/d32da348c4de2379482a48661ce968a55eebe5c4
- https://github.com/phpmyadmin/phpmyadmin/commit/d32da348c4de2379482a48661ce968a55eebe5c4
- GLSA-201505-03
- GLSA-201505-03
Modified: 2024-11-21
CVE-2014-8959
Directory traversal vulnerability in libraries/gis/GIS_Factory.class.php in the GIS editor in phpMyAdmin 4.0.x before 4.0.10.6, 4.1.x before 4.1.14.7, and 4.2.x before 4.2.12 allows remote authenticated users to include and execute arbitrary local files via a crafted geometry-type parameter.
- openSUSE-SU-2014:1561
- openSUSE-SU-2014:1561
- MDVSA-2014:228
- MDVSA-2014:228
- http://www.phpmyadmin.net/home_page/security/PMASA-2014-14.php
- http://www.phpmyadmin.net/home_page/security/PMASA-2014-14.php
- 71247
- 71247
- https://github.com/phpmyadmin/phpmyadmin/commit/80cd40b6687a6717860d345d6eb55bef2908e961
- https://github.com/phpmyadmin/phpmyadmin/commit/80cd40b6687a6717860d345d6eb55bef2908e961
- GLSA-201505-03
- GLSA-201505-03
Modified: 2024-11-21
CVE-2014-8960
Cross-site scripting (XSS) vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename.
- openSUSE-SU-2014:1561
- openSUSE-SU-2014:1561
- MDVSA-2014:228
- MDVSA-2014:228
- http://www.phpmyadmin.net/home_page/security/PMASA-2014-15.php
- http://www.phpmyadmin.net/home_page/security/PMASA-2014-15.php
- 71244
- 71244
- https://github.com/phpmyadmin/phpmyadmin/commit/9364e2eee5681681caf7205c0933bc18af11e233
- https://github.com/phpmyadmin/phpmyadmin/commit/9364e2eee5681681caf7205c0933bc18af11e233
- GLSA-201505-03
- GLSA-201505-03
Modified: 2024-11-21
CVE-2014-8961
Directory traversal vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to obtain potentially sensitive information about a file's line count via a crafted parameter.
- openSUSE-SU-2014:1561
- openSUSE-SU-2014:1561
- MDVSA-2014:228
- MDVSA-2014:228
- http://www.phpmyadmin.net/home_page/security/PMASA-2014-16.php
- http://www.phpmyadmin.net/home_page/security/PMASA-2014-16.php
- 71245
- 71245
- https://github.com/phpmyadmin/phpmyadmin/commit/b99b6b6672ff2419f05b05740c80c7a23c1da994
- https://github.com/phpmyadmin/phpmyadmin/commit/b99b6b6672ff2419f05b05740c80c7a23c1da994
- GLSA-201505-03
- GLSA-201505-03