CVE-2008-4326
Published: 30 September 2008
The PMA_escapeJsString function in libraries/js_escape.lib.php in phpMyAdmin before 2.11.9.2, when Internet Explorer is used, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via a NUL byte inside a "</script" sequence.
Priority
Status
Package | Release | Status |
---|---|---|
phpmyadmin Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
feisty |
Ignored
(end of life, was needs-triage)
|
|
gutsy |
Ignored
(end of life, was needs-triage)
|
|
hardy |
Released
(4:2.11.3-1ubuntu1.2)
|
|
intrepid |
Released
(4:2.11.8.1-1ubuntu0.1)
|
|
jaunty |
Not vulnerable
(4:3.1.2-1)
|
|
karmic |
Not vulnerable
(4:3.2.0.1-1)
|
|
upstream |
Released
(4:2.11.8.1-3)
|
|
Patches: upstream: http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/branches/MAINT_2_11_9/phpMyAdmin/libraries/js_escape.lib.php?view=patch&r1=11514&r2=11603&pathrev=11603 |