Follow us on Twitter or via RSS feeds with tweets or complete announcement texts or excerpts
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Tue, 24 May 2011 07:59:08 -0400 (EDT)
From: Josh Bressers <bressers@...hat.com>
To: oss-security@...ts.openwall.com
Cc: Robert Scheck <robert@...oraproject.org>,
        "Steven M. Christey" <coley@...us.mitre.org>
Subject: Re: CVE Request -- phpMyAdmin -- PMASA-2011-3 &
 PMASA-2011-4

----- Original Message -----
> Hello, Josh, Steve, vendors,
> 
> the following two security flaws have been recently reported against
> phpMyAdmin:
> [1] http://www.phpmyadmin.net/home_page/security/PMASA-2011-3.php

This one is an XSS flaw. Use CVE-2011-1940.


> [2] http://www.phpmyadmin.net/home_page/security/PMASA-2011-4.php

This one is a URL redirection flaw. Use CVE-2011-1941


> References:
> [3] http://bugs.gentoo.org/show_bug.cgi?id=368495
> 

Thanks.

-- 
    JB

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ