PMASA-2008-9
Announcement-ID: PMASA-2008-9
Date: 2008-10-30
Summary
XSS on a Designer component
Description
A logged-in user can be subject of cross site scripting attack via the pmd_pdf.php script.
Severity
We consider this vulnerability to be serious.
Affected Versions
For 2.11.x: versions before 2.11.9.3.<br /> For 3.0.x: versions before 3.0.1.1.<br />
Solution
Upgrade to phpMyAdmin 2.11.9.3 or 3.0.1.1.
References
Advisory: http://www.securityfocus.com/bid/31928/info
Assigned CVE IDs: CVE-2008-4775
Patches
The following commits have been made to fix this issue:
The following commits have been made on the 2.11 branch to fix this issue:
More information
For further information and in case of questions, please contact the phpMyAdmin security team at security@phpmyadmin.net.