phpMyAdmin 3.5.x < 3.5.3 Multiple Vulnerabilities (PMASA-2012-6 - PMASA-2012-7)

This script is Copyright (C) 2012-2014 Tenable Network Security, Inc.


Synopsis :

The remote web server hosts a PHP application that is affected by
multiple vulnerabilities.

Description :

According to its self-identified version number, the phpMyAdmin 3.5.x
install hosted on the remote web server is earlier than 3.5.3 and is,
therefore, affected by multiple vulnerabilities :

- When creating or modifying a trigger, event, or
procedure with a crafted name, it is possible for a user
to trigger a cross-site scripting (XSS) attack.

- A man-in-the-middle (MITM) attack is possible when
fetching the version information from a non-SSL site.
To display information about the current phpMyAdmin
version, a piece of JavaScript is fetched from the
phpmyadmin.net website in non-SSL mode. A MITM attack
could modify this script on the wire.

See also :

http://www.phpmyadmin.net/home_page/security/PMASA-2012-6.php
http://www.phpmyadmin.net/home_page/security/PMASA-2012-7.php

Solution :

Either upgrade to phpMyAdmin 3.5.3 or later, or apply the patches from
the referenced links.

Risk factor :

Low / CVSS Base Score : 3.5
(CVSS2#AV:N/AC:M/Au:S/C:N/I:P/A:N)
CVSS Temporal Score : 2.9
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: CGI abuses : XSS

Nessus Plugin ID: 62663 ()

Bugtraq ID: 55925
55939

CVE ID: CVE-2012-5339
CVE-2012-5368