CVE Database

CVE-2013-1937

Impact: Moderate
Public: 2013-04-09
Bugzilla: 950102: CVE-2013-1937 phpMyAdmin: XSS flaw when displaying GIS Visualization(s) (PMASA-2013-1)

Details

The MITRE CVE dictionary describes this issue as:

Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might allow remote attackers to inject arbitrary web script or HTML via the (1) visualizationSettings[width] or (2) visualizationSettings[height] parameter.

Find out more about CVE-2013-1937 from the MITRE CVE dictionary and NIST NVD.

CVSS v2 metrics

NOTE: The following CVSS v2 metrics and score provided are preliminary and subject to review.

Base Score: 2.6
Base Metrics: AV:N/AC:H/Au:N/C:N/I:P/A:N
Access Vector: Network
Access Complexity: High
Authentication: None
Confidentiality Impact: None
Integrity Impact: Partial
Availability Impact: None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat security errata

Platform Errata Release Date

External References

http://www.phpmyadmin.net/home_page/security/PMASA-2013-1.php

This page is generated automatically and has not been checked for errors or omissions.

For clarification or corrections please contact the Red Hat Security Response Team.