← Voltar para CVEs
CVE-2012-5368
N/ADescricao
phpMyAdmin 3.5.x before 3.5.3 uses JavaScript code that is obtained through an HTTP session to phpmyadmin.net without SSL, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by modifying this code.
Detalhes CVE
Pontuacao CVSS v3.1N/A
Publicado10/25/2012
Ultima modificacao4/29/2026
Fontenvd
Avistamentos honeypot0
Produtos afetados
phpmyadmin:phpmyadmin
Fraquezas (CWE)
CWE-79
Referencias
http://www.securityfocus.com/bid/55939(cve@mitre.org)
https://github.com/phpmyadmin/phpmyadmin/commit/50edafc0884aa15d0a1aa178089ac6a1ad2eb18a(cve@mitre.org)
https://github.com/phpmyadmin/phpmyadmin/commit/a547f3d3e2cf36c6a904fa3e053fd8bddd3fbbb0(cve@mitre.org)
http://lists.opensuse.org/opensuse-updates/2012-11/msg00033.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.phpmyadmin.net/home_page/security/PMASA-2012-7.php(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/55939(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/phpmyadmin/phpmyadmin/commit/50edafc0884aa15d0a1aa178089ac6a1ad2eb18a(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/phpmyadmin/phpmyadmin/commit/a547f3d3e2cf36c6a904fa3e053fd8bddd3fbbb0(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.