Menu

#4501 (ok 4.0.10.2) XSS in table browse page

4.0.10
fixed
None
1
2014-08-17
2014-08-06
No

Steps: In table browse page, try to delete a row from a table where either the database name, table name or a column name is crafted ()

Affected versions: 4.0.x, 4.1.x, 4.2.x

Problematic line: sql.js L122 (in QA_4_2) "var question = $.sprintf(PMA_messages.strDoYouReally, $(this).closest('td').find('div').text());"

Discussion

  • Marc Delisle

    Marc Delisle - 2014-08-17
    • private: Yes --> No
     
  • Marc Delisle

    Marc Delisle - 2014-08-17
    • summary: XSS in table browse page --> (ok 4.0.10.2) XSS in table browse page
    • status: open --> fixed
    • assigned_to: Madhura Jayaratne
    • Priority: 5 --> 1
     
Want the latest updates on software, tech news, and AI?
Get latest updates about software, tech news, and AI from SourceForge directly in your inbox once a month.