Candidate: CVE-2014-9219 PublicDate: 2014-12-08 11:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9219 https://github.com/phpmyadmin/phpmyadmin/commit/9b2479b7216dd91a6cc2f231c0fd6b85d457f6e2 http://www.phpmyadmin.net/home_page/security/PMASA-2014-18.php Description: Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_phpmyadmin: upstream_phpmyadmin: needs-triage lucid_phpmyadmin: ignored (reached end-of-life) precise_phpmyadmin: ignored (reached end-of-life) precise/esm_phpmyadmin: DNE (precise was needed) trusty_phpmyadmin: ignored (out of standard support) trusty/esm_phpmyadmin: needed utopic_phpmyadmin: ignored (reached end-of-life) vivid_phpmyadmin: not-affected (4:4.2.12-2) vivid/stable-phone-overlay_phpmyadmin: DNE vivid/ubuntu-core_phpmyadmin: DNE wily_phpmyadmin: not-affected (4:4.2.12-2) xenial_phpmyadmin: not-affected (4:4.2.12-2) yakkety_phpmyadmin: not-affected (4:4.2.12-2) zesty_phpmyadmin: not-affected (4:4.2.12-2) artful_phpmyadmin: not-affected (4:4.2.12-2) bionic_phpmyadmin: not-affected (4:4.2.12-2) cosmic_phpmyadmin: not-affected (4:4.2.12-2) disco_phpmyadmin: not-affected (4:4.2.12-2) eoan_phpmyadmin: DNE focal_phpmyadmin: not-affected (4:4.2.12-2) groovy_phpmyadmin: not-affected (4:4.2.12-2) hirsute_phpmyadmin: not-affected (4:4.2.12-2) impish_phpmyadmin: not-affected (4:4.2.12-2) jammy_phpmyadmin: not-affected (4:4.2.12-2) devel_phpmyadmin: not-affected (4:4.2.12-2)