Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2014-1879

Overview

Vulnerability Score 3.5 3.5
CVE Id CVE-2014-1879
Last Modified 05 Aug 2015 12:28:42
Published 20 Feb 2014 10:27:09
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication SINGLE_INSTANCE

CVE-2014-1879

Summary

Cross-site scripting (XSS) vulnerability in import.php in phpMyAdmin before 4.1.7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename in an import action.

Vulnerable Systems

Application

  • Phpmyadmin 1.0.0

  • Phpmyadmin 1.0.1

  • Phpmyadmin 1.0.2

  • Phpmyadmin 1.0.3

  • Phpmyadmin 1.0.4

  • Phpmyadmin 1.0.5

  • Phpmyadmin 1.0.6

  • Phpmyadmin 1.0.7

  • Phpmyadmin 1.0.8

  • Phpmyadmin 1.1

  • Phpmyadmin 1.2

  • Phpmyadmin 1.2.1

  • Phpmyadmin 1.2.2

  • Phpmyadmin 1.2.3

  • Phpmyadmin 1.2.4

  • Phpmyadmin 1.2.5

  • Phpmyadmin 1.2.6

  • Phpmyadmin 1.2.7

  • Phpmyadmin 1.2.8

  • Phpmyadmin 1.2.9

  • Phpmyadmin 1.2.9.1

  • Phpmyadmin 1.2.9.2

  • Phpmyadmin 1.2.9.3

  • Phpmyadmin 1.2.9.4

  • Phpmyadmin 1.2.9.5

  • Phpmyadmin 1.3

  • Phpmyadmin 2.11.0

  • Phpmyadmin 2.11.1.0

  • Phpmyadmin 2.11.1.1

  • Phpmyadmin 2.11.1.2

  • Phpmyadmin 2.11.10.0

  • Phpmyadmin 2.11.10.1

  • Phpmyadmin 2.11.2.0

  • Phpmyadmin 2.11.2.1

  • Phpmyadmin 2.11.2.2

  • Phpmyadmin 2.11.3.0

  • Phpmyadmin 2.11.4.0

  • Phpmyadmin 2.11.5.0

  • Phpmyadmin 2.11.5.1

  • Phpmyadmin 2.11.5.2

  • Phpmyadmin 2.11.6.0

  • Phpmyadmin 2.11.7.0

  • Phpmyadmin 2.11.7.1

  • Phpmyadmin 2.11.8.0

  • Phpmyadmin 2.11.9.0

  • Phpmyadmin 2.11.9.1

  • Phpmyadmin 2.11.9.2

  • Phpmyadmin 2.11.9.3

  • Phpmyadmin 2.11.9.4

  • Phpmyadmin 2.11.9.5

  • Phpmyadmin 2.11.9.6

  • Phpmyadmin 3.0.0

  • Phpmyadmin 3.0.1

  • Phpmyadmin 3.0.1.1

  • Phpmyadmin 3.1.0

  • Phpmyadmin 3.1.1

  • Phpmyadmin 3.1.2

  • Phpmyadmin 3.1.3

  • Phpmyadmin 3.1.3.1

  • Phpmyadmin 3.1.3.2

  • Phpmyadmin 3.1.4

  • Phpmyadmin 3.1.5

  • Phpmyadmin 3.2.0

  • Phpmyadmin 3.2.1

  • Phpmyadmin 3.2.2

  • Phpmyadmin 3.3.0.0

  • Phpmyadmin 3.3.1.0

  • Phpmyadmin 3.3.10.0

  • Phpmyadmin 3.3.2.0

  • Phpmyadmin 3.3.3.0

  • Phpmyadmin 3.3.4.0

  • Phpmyadmin 3.3.5.0

  • Phpmyadmin 3.3.5.1

  • Phpmyadmin 3.3.6

  • Phpmyadmin 3.3.7

  • Phpmyadmin 3.3.8

  • Phpmyadmin 3.3.8.1

  • Phpmyadmin 3.3.9.0

  • Phpmyadmin 3.3.9.1

  • Phpmyadmin 3.3.9.2

  • Phpmyadmin 3.4.0.0

  • Phpmyadmin 3.4.1.0

  • Phpmyadmin 3.4.10.0

  • Phpmyadmin 3.4.10.1

  • Phpmyadmin 3.4.10.2

  • Phpmyadmin 3.4.11

  • Phpmyadmin 3.4.2.0

  • Phpmyadmin 3.4.3.0

  • Phpmyadmin 3.4.3.1

  • Phpmyadmin 3.4.3.2

  • Phpmyadmin 3.4.4.0

  • Phpmyadmin 3.4.5.0

  • Phpmyadmin 3.4.6.0

  • Phpmyadmin 3.4.7.0

  • Phpmyadmin 3.4.7.1

  • Phpmyadmin 3.4.8.0

  • Phpmyadmin 3.4.9.0

  • Phpmyadmin 3.5.0.0

  • Phpmyadmin 3.5.1.0

  • Phpmyadmin 3.5.2.0

  • Phpmyadmin 3.5.2.1

  • Phpmyadmin 3.5.2.2

  • Phpmyadmin 3.5.3.0

  • Phpmyadmin 3.5.4

  • Phpmyadmin 3.5.5

  • Phpmyadmin 3.5.6

  • Phpmyadmin 3.5.7

  • Phpmyadmin 3.5.8

  • Phpmyadmin 3.5.8.1

  • Phpmyadmin 3.5.8.2

  • Phpmyadmin 4.0.0

  • Phpmyadmin 4.0.1

  • Phpmyadmin 4.0.2

  • Phpmyadmin 4.0.3

  • Phpmyadmin 4.0.4

  • Phpmyadmin 4.0.4.1

  • Phpmyadmin 4.0.4.2

  • Phpmyadmin 4.0.5

  • Phpmyadmin 4.0.6

  • Phpmyadmin 4.0.7

  • Phpmyadmin 4.0.8

  • Phpmyadmin 4.0.9

  • Phpmyadmin 4.1.0

  • Phpmyadmin 4.1.1

  • Phpmyadmin 4.1.2

  • Phpmyadmin 4.1.3

  • Phpmyadmin 4.1.4

  • Phpmyadmin 4.1.5

  • Phpmyadmin 4.1.6


References

CONFIRM - https://github.com/phpmyadmin/phpmyadmin/commit/968d5d5f486820bfa30af046f063b9f23304e14a

CONFIRM - http://www.phpmyadmin.net/home_page/security/PMASA-2014-1.php

SUSE - openSUSE-SU-2014:0344

SECUNIA - 59832

BID - 65717


Last Updated: 27 May 2016 11:04:30