| Home Forum Radio Memberlist Help Search Quick Links |
| Forum Index » Internet » Security Alerts and vulnerabilities » PHPMyAdmin Vulnerability |
| Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here.. |
![]() |
![]() |
|
Thread Tools | Display Modes | ![]() |
|
#1
|
||||
|
||||
|
Nicolas Gregoire has reported two vulnerabilities in phpMyAdmin, which can be exploited by malicious people to compromise a vulnerable system and by malicious users to disclose sensitive information.
1) An input validation error in the handling of MySQL data allows injection of arbitrary shell commands. Example: F\';[command]\'A Successful exploitation requires that PHP safe mode is disabled and MIME-based external transformations are activated. The vulnerability has been reported in versions 2.6.0-pl2 up to 2.6.1-rc1. 2) Input passed to "sql_localfile" is not properly sanitised in "read_dump.php" before being used to disclose files. Successful exploitation requires access to the phpMyAdmin interface, and that PHP safe mode is disabled and the UploadDir mechanism to be active. The vulnerability has been reported in versions 2.4.0 up to 2.6.1-rc1. Solution: The vulnerabilities have been fixed in version 2.6.1-rc1. http://www.phpmyadmin.net/home_page/securi...ue=PMASA-2004-4 |
|
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| RSS-Microsoft Security Advisory (899480): Vulnerability in TCP Could Allow Connection Reset - 5/18/2005 | RSS Importer | Security Alerts and vulnerabilities | 0 | 05-18-2005 02:00 AM |
| WinAMP--Buffer Overflow Vulnerability | Mobo | Security Alerts and vulnerabilities | 0 | 01-28-2005 07:13 PM |
| Itunes Vulnerability | Mobo | Security Alerts and vulnerabilities | 0 | 01-14-2005 07:24 AM |
| Sun Java Plug-in vulnerability | Mobo | Security Alerts and vulnerabilities | 0 | 11-29-2004 04:28 PM |
|
|
||