LxCenter HyperVM & Kloxo Support

Forum



Members   Search      Help    Register    Login    Home
Home » Archive » Product Security » phpMyAdmin Cross-Site Scripting Vulnerabilities(versions prior to 3.3.5.1 and 2.11.10.1.)
icon4.gif  phpMyAdmin Cross-Site Scripting Vulnerabilities [message #76478] Fri, 20 August 2010 17:59 Go to next message
Ice-Man is currently offline Ice-Man  Switzerland
Messages: 93
Registered: September 2008
Valuable Member
DESCRIPTION:
Some vulnerabilities have been reported in phpMyAdmin, which can be
exploited by malicious people to conduct cross-site scripting
attacks.

1) Input passed via the "field_str" parameter to db_search.php , the
"delimiter" parameter to db_sql.php, the "sort" parameter to
db_structure.php, the "db" parameter to js/messages.php, the
"sort_by" parameter to server_databases.php, the "checkprivs",
"dbname", "pred_tablename", "selected_usr[]", "tablename", and
"username" parameters to server_privileges.php, the "DefaultLang"
parameter to setup/config.php, the "cpurge", "goto", "purge",
"purgekey", "table", and "zero_rows" parameters to sql.php, and the
"fields[multi_edit][]" parameter to tbl_replace.php is not properly
sanitised before being returned to the user. This can be exploited to
execute arbitrary HTML and script code in a user's browser session in
context of an affected site.

2) Certain unspecified input is not properly sanitised before being
returned to the user. This can be exploited to execute arbitrary HTML
and script code in a user's browser session in context of an affected
site.

The vulnerabilities are reported in versions prior to 3.3.5.1 and
2.11.10.1.

SOLUTION:
Update to version 3.3.5.1 or 2.11.10.1

http://www.phpmyadmin.net/home_page/security/PMASA-2010-5.ph p

[Updated on: Fri, 20 August 2010 17:59]

Report message to a moderator

Re: phpMyAdmin Cross-Site Scripting Vulnerabilities [message #77013 is a reply to message #76478] Sun, 26 September 2010 14:10 Go to previous messageGo to next message
heyhey is currently offline heyhey  Singapore
Messages: 9
Registered: June 2009
Member
I wonder why your SVN hasn't been updated with the new version!
Re: phpMyAdmin Cross-Site Scripting Vulnerabilities [message #77028 is a reply to message #77013] Tue, 28 September 2010 13:17 Go to previous message
Walter  Brazil
Messages: 866
Registered: February 2009
Location: Florianopolis / BR
Senior Master
Forum Moderator
LxCenter Project Manager

Maybe if you ask in the right place you will get an answer. Smile

See http://project.lxcenter.org/issues/283 .
Previous Topic:What is the current state of affairs?
Next Topic:Kloxo FCKEditor from 2003 suffer from CVE
Goto Forum:
  


Current Time: Wed Jun 19 17:13:05 EDT 2013

Total time taken to generate the page: 0.02695 seconds
.:: Contact :: Home :: Privacy ::.

Click here to lend your support to: LxCenter and make a donation at www.pledgie.com !

Powered by: FUDforum 3.0.2.
Copyright ©2001-2010 FUDforum Bulletin Board Software