← Back

CVE-2014-8326

nvd nist
Published: Nov 5, 2014Modified: May 6, 2026

JSON object

Loading...
3.5
Vector
AV:N/AC:M/Au:S/C:N/I:P/A:N
Exploitability: 6.8 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.5, 4.1.x before 4.1.14.6, and 4.2.x before 4.2.10.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name, related to the libraries/DatabaseInterface.class.php code for SQL debug output and the js/server_status_monitor.js code for the server monitor page.

Affected (55)

1 product
Phpmyadmin
1 product
Opensuse
Configuration A
53 vulnerable
Vulnerable SoftwareAffected Versions
Phpmyadmin
Version 4.0.0
Version 4.0.0 rc2
Version 4.0.0 rc3
Version 4.0.10.0
Version 4.0.10.1
Version 4.0.10.2
Version 4.0.10.3
Version 4.0.10.4
Version 4.0.10
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4.1
Version 4.0.4.2
Version 4.0.4
Version 4.0.5
Version 4.0.6
Version 4.0.7
Version 4.0.8
Version 4.0.9
Version 4.1.0
Version 4.1.10
Version 4.1.11
Version 4.1.12
Version 4.1.13
Version 4.1.14.1
Version 4.1.14.2
Version 4.1.14.3
Version 4.1.14.4
Version 4.1.14.5
Version 4.1.14
Version 4.1.1
Version 4.1.2
Version 4.1.3
Version 4.1.4
Version 4.1.5
Version 4.1.6
Version 4.1.7
Version 4.1.8
Version 4.1.9
Version 4.2.0
Version 4.2.10
Version 4.2.1
Version 4.2.2
Version 4.2.3
Version 4.2.4
Version 4.2.5
Version 4.2.6
Version 4.2.7.1
Version 4.2.7
Version 4.2.8.1
Version 4.2.8
Version 4.2.9
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 13.1
Version 13.2

Timeline

No history available yet.