phpMyAdmin error.php BBcode Tag XSS (PMASA-2010-9)

This script is Copyright (C) 2011-2016 Tenable Network Security, Inc.


Synopsis :

The remote web server hosts a PHP script that is prone to a cross-
site scripting attack.

Description :

The version of phpMyAdmin fails to validate BBcode tags in user input
to the 'error' parameter of the 'error.php' script before using it to
generate dynamic HTML.

An attacker may be able to leverage this issue to inject arbitrary
HTML or script code into a user's browser to be executed within the
security context of the affected site. For example, this could be
used to cause a page with arbitrary text and a link to an external
site to be displayed.

See also :

http://www.phpmyadmin.net/home_page/security/PMASA-2010-9.php

Solution :

Upgrade to phpMyAdmin 3.4.0-beta1 or later.

Risk factor :

Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS Temporal Score : 3.4
(CVSS2#E:POC/RL:OF/RC:C)
Public Exploit Available : true

Family: CGI abuses : XSS

Nessus Plugin ID: 51425 ()

Bugtraq ID: 45633

CVE ID: CVE-2010-4480

Ready to Scan Unlimited IPs & Run Compliance Checks?

Upgrade to Nessus Professional today!

Buy Now

Combine the Power of Nessus with the Ease of Cloud

Start your free Nessus Cloud trial now!

Begin Free Trial