Description
Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might allow remote attackers to inject arbitrary web script or HTML via the (1) visualizationSettings[width] or (2) visualizationSettings[height] parameter. NOTE: a third party reports that this is "not exploitable.
Remediation
References
Related Vulnerabilities
Oracle JRE Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2024-21011)
WordPress Plugin Poll, Survey, Questionnaire and Voting system SQL Injection (1.5.2)
WordPress Plugin Abandoned Cart Pro for WooCommerce Cross-Site Scripting (7.11.1)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-0703)