Updated phpmyadmin package fixes security vulnerability
Publication date: 23 Oct 2014Modification date: 23 Oct 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-8326
Description
In phpMyAdmin before 4.1.14.6, with a crafted database or table name it is possible to trigger an XSS in SQL debug output when enabled and in server monitor page when viewing and analysing executed queries (CVE-2014-8326).
References
SRPMS
4/core
- phpmyadmin-4.1.14.6-1.mga4
3/core
- phpmyadmin-4.1.14.6-1.mga3