PMASA-2010-9
Announcement-ID: PMASA-2010-9
Date: 2010-12-07
Updated: 2010-02-16
Summary
Unvalidated input on error page.
Description
It was possible to display arbitrary text and link to external site using parameters passed to particular script.
Severity
This issue is considered minor, because the only purpose of affected file is to display an error message.
Affected Versions
All versions prior to 3.4.0-beta1.
Solution
Upgrade to phpMyAdmin 3.4.0-beta1 or newer or apply patch listed below. Due to its minor impact, a fix will be included in the next regular release which is 3.3.10.
References
This issue was reported by Tiger Security Team.
Assigned CVE IDs: CVE-2010-4480
Patches
The following commits have been made to fix this issue:
The following commits have been made on the 2.11 branch to fix this issue:
The following commits have been made on the 3.3 branch to fix this issue:
More information
For further information and in case of questions, please contact the phpMyAdmin security team at security@phpmyadmin.net.