Advisories ยป MGASA-2014-0420

Updated phpmyadmin package fixes security vulnerability

Publication date: 23 Oct 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-8326

Description

In phpMyAdmin before 4.1.14.6, with a crafted database or table name it is
possible to trigger an XSS in SQL debug output when enabled and in server
monitor page when viewing and analysing executed queries (CVE-2014-8326).
                

References

SRPMS

3/core

4/core