Candidate: CVE-2012-1600 PublicDate: 2014-05-14 00:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1600 http://www.openwall.com/lists/oss-security/2012/03/28 Description: Multiple cross-site scripting (XSS) vulnerabilities in functions.php in phpPgAdmin before 5.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) type of a function. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Mateusz Goik Assigned-to: CVSS: Patches_phppgadmin: upstream: https://github.com/phppgadmin/phppgadmin/commit/74174ad639664b52cc1609ede0af8bc403e98a00 upstream_phppgadmin: released (5.0.4) hardy_phppgadmin: ignored (reached end-of-life) lucid_phppgadmin: ignored (reached end-of-life) maverick_phppgadmin: ignored (reached end-of-life) natty_phppgadmin: ignored (reached end-of-life) oneiric_phppgadmin: ignored (reached end-of-life) precise_phppgadmin: ignored (reached end-of-life) precise/esm_phppgadmin: DNE (precise was needed) quantal_phppgadmin: not-affected (5.0.4-1) raring_phppgadmin: not-affected (5.0.4-1) saucy_phppgadmin: not-affected (5.0.4-1) trusty_phppgadmin: not-affected (5.0.4-1) trusty/esm_phppgadmin: DNE (trusty was not-affected [5.0.4-1]) utopic_phppgadmin: not-affected (5.0.4-1) vivid_phppgadmin: not-affected (5.0.4-1) vivid/stable-phone-overlay_phppgadmin: DNE vivid/ubuntu-core_phppgadmin: DNE wily_phppgadmin: not-affected (5.0.4-1) xenial_phppgadmin: not-affected (5.0.4-1) yakkety_phppgadmin: not-affected (5.0.4-1) zesty_phppgadmin: not-affected (5.0.4-1) devel_phppgadmin: not-affected (5.0.4-1)