CVE-2010-4480
EPSS 7.5%
Description
error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1, allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted BBcode tag containing "@" characters, as demonstrated using "[a@url@page]".
How to fix CVE-2010-4480
To remediate CVE-2010-4480, upgrade the affected package to a fixed version below.
- Debian/phpmyadmin—upgrade to 4:3.3.7-3 or later
Is CVE-2010-4480 being exploited?
Moderate — EPSS is 7.5%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 4:3.3.7-3