CVE-2012-5368
Publication date 25 October 2012
Last updated 24 July 2024
Ubuntu priority
phpMyAdmin 3.5.x before 3.5.3 uses JavaScript code that is obtained through an HTTP session to phpmyadmin.net without SSL, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by modifying this code.
Status
Package | Ubuntu Release | Status |
---|---|---|
phpmyadmin | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
|