Cross-site scripting (XSS) vulnerability in the micro history implementation in phpMyAdmin 4.0.x before 4.0.10.3, 4.1.x before 4.1.14.4, and 4.2.x before 4.2.8.1 allows remote attackers to inject arbitrary web script or HTML, and consequently conduct a cross-site request forgery (CSRF) attack to create a root account, via a crafted URL, related to js/ajax.js.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2014-11-08 11:55
Updated : 2024-02-04 18:35
NVD link : CVE-2014-6300
Mitre link : CVE-2014-6300
CVE.ORG link : CVE-2014-6300
JSON object : View
Products Affected
phpmyadmin
- phpmyadmin
opensuse
- opensuse
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')