Back to search
CVE-2010-4480
Published: Dec 8, 2010
Modified: Aug 7, 2024
PUBLISHED
Description
error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1, allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted BBcode tag containing "@" characters, as demonstrated using "[a@url@page]".
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
ADV-2011-0027
vdb-entry
x_refsource_VUPEN
ADV-2011-0001
vdb-entry
x_refsource_VUPEN
45633
vdb-entry
x_refsource_BID
42485
third-party-advisory
x_refsource_SECUNIA
DSA-2139
vendor-advisory
x_refsource_DEBIAN
15699
exploit
x_refsource_EXPLOIT-DB
http://www.phpmyadmin.net/home_page/security/PMASA-2010-9.php
x_refsource_CONFIRM
ADV-2010-3133
vdb-entry
x_refsource_VUPEN
42725
third-party-advisory
x_refsource_SECUNIA
MDVSA-2011:000
vendor-advisory
x_refsource_MANDRIVA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now