Description
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) table name, (2) SET value, (3) search query, or (4) hostname in a Location header.
Remediation
References
Related Vulnerabilities
WordPress Plugin Invoicing with InvoiceXpress for WooCommerce-Free Cross-Site Scripting (3.0.2)
Liferay DXP Insufficient Session Expiration Vulnerability (CVE-2025-43819)
WordPress Plugin WordPress Download Manager Cross-Site Scripting (2.9.51)
MySQL CVE-2013-5908 Vulnerability (CVE-2013-5908)
WordPress Plugin Vodpod Video Gallery 'gid' Parameter Cross-Site Scripting (3.1.5)