CVE-2011-3181
EPSS 0.60%
Description
Multiple cross-site scripting (XSS) vulnerabilities in the Tracking feature in phpMyAdmin 3.3.x before 3.3.10.4 and 3.4.x before 3.4.4 allow remote attackers to inject arbitrary web script or HTML via a (1) table name, (2) column name, or (3) index name.
How to fix CVE-2011-3181
To remediate CVE-2011-3181, upgrade the affected package to a fixed version below.
- Debian/phpmyadmin—upgrade to 4:3.4.4-1 or later
Is CVE-2011-3181 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4:3.4.4-1