vulnerability 9515
phpMyAdmin: Cross Site Scripting of db_create.php
Synthesis of the vulnerability
| An attacker can use the database creation feature to generate a Cross Site Scripting in phpMyAdmin. |
Severity: 2/4.
Creation date: 15/03/2010.
|
Description of the vulnerability
The phpMyAdmin server is used to administer a MySQL database via a web browser.
The db_create.php script creates a database. The parameter "new_db" indicates the database name.
However, the "new_db" parameter is not filtered before beeing displayed on the web page.
An attacker can therefore use the database creation feature to generate a Cross Site Scripting in phpMyAdmin. |
Complete Vigil@nce bulletin
Characteristics
Title: phpMyAdmin: Cross Site Scripting of db_create.php.
Keywords: Cross MySQL Scripting Site db_create new_db phpMyAdmin.
Identifiers: BID-38707, VIGILANCE-VUL-9515.
|
Information sources
Supplements
Computer vulnerabilities tracking service
The Vigil@nce computer vulnerability tracking service alerts your teams of vulnerabilities or threats impacting your information system.
The Vigil@nce vulnerability database contains several thousand vulnerabilities.
This bulletin is published by the Vigil@nce team, which tracks computer vulnerabilities impacting systems and applications.
Computer applications vulnerability