CVE-2014-4348
https://notcve.org/view.php?id=CVE-2014-4348
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name that is improperly handled after presence in (a) the favorite list or (b) recent tables. Múltiples vulnerabilidades de XSS en phpMyAdmin 4.2.x anterior a 4.2.4 permiten a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de un nombre manipulado de (1) base de datos o (2) de tabla que no se maneja debidamente después de su presencia en (a) la lista de favoritos o (b) tablas recientes. • http://phpmyadmin.net/home_page/security/PMASA-2014-2.php http://www.securityfocus.com/bid/68201 https://github.com/phpmyadmin/phpmyadmin/commit/cb7c703c03f656debcea2a16468bd53660fc888e https://github.com/phpmyadmin/phpmyadmin/commit/d18a2dd9faad7e0e96df799b59e16ef587afb838 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •