| Name | CVE-2013-1937 | 
| Description | Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might allow remote attackers to inject arbitrary web script or HTML via the (1) visualizationSettings[width] or (2) visualizationSettings[height] parameter. NOTE: a third party reports that this is "not exploitable. | 
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) | 
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status | 
|---|
| phpmyadmin (PTS) | bullseye | 4:5.0.4+dfsg2-2+deb11u1 | fixed | 
|  | bullseye (security) | 4:5.0.4+dfsg2-2+deb11u2 | fixed | 
|  | bookworm | 4:5.2.1+dfsg-1+deb12u1 | fixed | 
|  | trixie | 4:5.2.2-really+dfsg-1 | fixed | 
|  | forky, sid | 4:5.2.3+dfsg-1 | fixed | 
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs | 
|---|
| phpmyadmin | source | (unstable) | (not affected) |  |  |  | 
Notes
- phpmyadmin <not-affected> (Affected are versions 3.5.0 to 3.5.7, older versions not vulnerable)
http://seclists.org/fulldisclosure/2013/Apr/100
https://github.com/phpmyadmin/phpmyadmin/commit/79089c9bc02c82c15419fd9d6496b8781ae08a5a