Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2013-3742

Published: 4 July 2013

Cross-site scripting (XSS) vulnerability in view_create.php (aka the Create View page) in phpMyAdmin 4.x before 4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via an invalid SQL CREATE VIEW statement with a crafted name that triggers an error message.

Priority

Medium

Status

Package Release Status
phpmyadmin
Launchpad, Ubuntu, Debian
lucid Not vulnerable
(4:3.3.2-1ubuntu1)
precise Not vulnerable
(4:3.4.10.1-1)
quantal Not vulnerable
(4:3.4.11.1-1)
raring Not vulnerable
(4:3.5.8.1-1)
saucy Not vulnerable
(4:4.0.6-1)
trusty Not vulnerable

upstream
Released (4:4.0.1-3)
Patches:
upstream: https://github.com/phpmyadmin/phpmyadmin/commit/9b3551601ce714adb5e3f428476052f0ec6093bf