Description
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x before 4.1.14.1 and 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name that is improperly handled after a (1) hide or (2) unhide action.
Remediation
References
Related Vulnerabilities
SharePoint Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-8580)
WordPress Plugin Store Locator Plus for WordPress SQL Injection (3.8.6)
Oracle Database Server CVE-2006-0287 Vulnerability (CVE-2006-0287)
WordPress Plugin Multiple Page Generator-MPG Cross-Site Request Forgery (3.3.9)