Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in MySql Lite Administrator (mysql-lite-administrator) beta-1 allow remote attackers to inject arbitrary web script or HTML via the table_name parameter to (1) tabella.php, (2) coloni.php, or (3) insert.php or (4) num_row parameter to coloni.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mysql-Lite-Administrator Project | Mysql-Lite-Administrator | - |
Related Weaknesses (CWE)
References
- http://hyp3rlinx.altervista.org/advisories/AS-MYSQLLITEADMINISTRATOR0621.txtExploit
- http://packetstormsecurity.com/files/132420/MySQL-Lite-Administrator-Beta-1-Cros
- http://www.securityfocus.com/archive/1/535809/100/0/threaded
- http://www.securityfocus.com/bid/75397
- http://hyp3rlinx.altervista.org/advisories/AS-MYSQLLITEADMINISTRATOR0621.txtExploit
- http://packetstormsecurity.com/files/132420/MySQL-Lite-Administrator-Beta-1-Cros
- http://www.securityfocus.com/archive/1/535809/100/0/threaded
- http://www.securityfocus.com/bid/75397
FAQ
What is CVE-2015-5064?
CVE-2015-5064 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Multiple cross-site scripting (XSS) vulnerabilities in MySql Lite Administrator (mysql-lite-administrator) beta-1 allow remote attackers to inject arbitrary web script or HTML via the table_name param...
How severe is CVE-2015-5064?
CVE-2015-5064 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-5064?
Check the references section above for vendor advisories and patch information. Affected products include: Mysql-Lite-Administrator Project Mysql-Lite-Administrator.