FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

phpmyadmin -- Cross-Site Scripting Vulnerability

Affected packages
phpMyAdmin < 2.11.9.2

Details

VuXML ID 150e4548-8950-11dd-a6fe-0030843d3802
Discovery 2008-09-23
Entry 2008-09-23
Modified 2008-10-03

Secunia reports:

An error exists in the "PMA_escapeJsString()" function in libraries/js_escape.lib.php, which can be exploited to bypass certain filters and execute arbitrary HTML and script code in a user's browser session in context of an affected site when e.g. Microsoft Internet Explorer is used.

References

URL http://secunia.com/Advisories/31974/
URL http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-8