Description
|
|
Multiple vulnerabilities have been identified in phpMyAdmin, which could be exploited to conduct spoofing or cross site scripting attacks.
The first issue is caused by a design error in various scripts (except "index.php") that fail to verify whether they are linked to another domain's frames, which could be exploited to conduct phishing attacks.
The second vulnerability is caused by an input validation error when loadind data from "config/config.inc.php" via "scripts/setup.php", which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected site.
|