VDB
CVE-2011-1940
CVE-2011-1940
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.3.x before 3.3.10.1 and 3.4.x before 3.4.1 allow remote attackers to inject arbitrary web script or HTML via a crafted table name that triggers improper HTML rendering on a Tracking page, related to (1) libraries/tbl_links.inc.php and (2) tbl_tracking.php.
EPSS 0.29% · 52.2th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
0.29%
52.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| phpmyadmin | phpmyadmin | 3.3.0, 3.4.0 |
| n/a | n/a | n/a |
| phpmyadmin | phpmyadmin | 3.3.2.0, 3.3.3.0, 3.3.5.0 |
Timeline
- Jan 26, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- DSA-2391 vendor-advisory
- http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin%3Ba=commitdiff%3Bh=7e10c132a3887c8ebfd7a8eee356b28375f1e287 url
- http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin%3Ba=commitdiff%3Bh=d3ccf798fdbd4f8a89d4088130637d8dee918492 url
- http://www.phpmyadmin.net/home_page/security/PMASA-2011-3.php url
- https://nvd.nist.gov/vuln/detail/CVE-2011-1940 advisory
- https://github.com/phpmyadmin/phpmyadmin package
- http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin;a=commitdiff;h=7e10c132a3887c8ebfd7a8eee356b28375f1e287 url
- http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin;a=commitdiff;h=d3ccf798fdbd4f8a89d4088130637d8dee918492 url