Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here..

Reply
 
Thread Tools Display Modes
  #1  
Old 12-14-2004, 07:59 AM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,574
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Nicolas Gregoire has reported two vulnerabilities in phpMyAdmin, which can be exploited by malicious people to compromise a vulnerable system and by malicious users to disclose sensitive information.

1) An input validation error in the handling of MySQL data allows injection of arbitrary shell commands.

Example:
F\';[command]\'A

Successful exploitation requires that PHP safe mode is disabled and MIME-based external transformations are activated.

The vulnerability has been reported in versions 2.6.0-pl2 up to 2.6.1-rc1.

2) Input passed to "sql_localfile" is not properly sanitised in "read_dump.php" before being used to disclose files.

Successful exploitation requires access to the phpMyAdmin interface, and that PHP safe mode is disabled and the UploadDir mechanism to be active.

The vulnerability has been reported in versions 2.4.0 up to 2.6.1-rc1.

Solution:
The vulnerabilities have been fixed in version 2.6.1-rc1.


http://www.phpmyadmin.net/home_page/securi...ue=PMASA-2004-4
Reply With Quote
Posted


Reply

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
RSS-Microsoft Security Advisory (899480): Vulnerability in TCP Could Allow Connection Reset - 5/18/2005 RSS Importer Security Alerts and vulnerabilities 0 05-18-2005 02:00 AM
WinAMP--Buffer Overflow Vulnerability Mobo Security Alerts and vulnerabilities 0 01-28-2005 07:13 PM
Itunes Vulnerability Mobo Security Alerts and vulnerabilities 0 01-14-2005 07:24 AM
Sun Java Plug-in vulnerability Mobo Security Alerts and vulnerabilities 0 11-29-2004 04:28 PM



All times are GMT -5. The time now is 05:30 AM.


Firefox 2