Miggo Logo

CVE-2012-4579: phpMyAdmin Multiple XSS Vulnerabilities

3.5

CVSS Score

Basic Information

EPSS Score
0.40767%
Published
5/17/2022
Updated
8/29/2023
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
AV:N/AC:M/Au:S/C:N/I:P/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
phpmyadmin/phpmyadmincomposer>= 3.5, < 3.5.2.23.5.2.2

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The provided vulnerability descriptions and advisories reference multiple XSS vectors related to table operations, triggers, and GIS visualization, but they do not explicitly name specific functions or file paths. While the phpMyAdmin security notice (PMASA-2012-4) lists commit hashes for patches, the actual code changes and affected functions cannot be analyzed without access to the commit diffs or source code. The vulnerability stems from insufficient output encoding of user-controlled inputs (e.g., table names) in various UI components, but mapping these to specific functions requires direct inspection of the patched code, which is unavailable here. Thus, no functions can be identified with high confidence.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

Multipl* *ross-sit* s*riptin* (XSS) vuln*r**iliti*s in p*pMy**min *.*.x ***or* *.*.*.* *llow r*mot* *ut**nti**t** us*rs to inj**t *r*itr*ry w** s*ript or *TML vi* * T**l* Op*r*tions (*) TRUN**T* or (*) *ROP link *or * *r**t** t**l* n*m*, (*) t** ***

Reasoning

T** provi*** vuln*r**ility **s*riptions *n* **visori*s r***r*n** multipl* XSS v**tors r*l*t** to t**l* op*r*tions, tri***rs, *n* *IS visu*liz*tion, *ut t**y *o not *xpli*itly n*m* sp**i*i* *un*tions or *il* p*t*s. W*il* t** `p*pMy**min` s**urity noti