Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.100450
Categoría:Web application abuses
Título:phpMyAdmin Insecure Temporary File and Directory Creation Vulnerabilities
Resumen:phpMyAdmin creates temporary directories and files in an insecure way.;; An attacker with local access could potentially exploit this issue to; perform symbolic-link attacks, overwriting arbitrary files in the; context of the affected application.
Descripción:Summary:
phpMyAdmin creates temporary directories and files in an insecure way.

An attacker with local access could potentially exploit this issue to
perform symbolic-link attacks, overwriting arbitrary files in the
context of the affected application.

Vulnerability Impact:
Successful attacks may corrupt data or cause denial-of-service
conditions. Other unspecified attacks are also possible.

Affected Software/OS:
This issue affects phpMyAdmin 2.11.x (prior to 2.11.10.)

Solution:
Updates are available. Please see the references for details.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2008-7251
BugTraq ID: 37826
http://www.securityfocus.com/bid/37826
Debian Security Information: DSA-2034 (Google Search)
http://www.debian.org/security/2010/dsa-2034
http://secunia.com/advisories/38211
http://secunia.com/advisories/39503
SuSE Security Announcement: SUSE-SR:2010:001 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.html
http://www.vupen.com/english/advisories/2010/0910
Common Vulnerability Exposure (CVE) ID: CVE-2008-7252
CopyrightCopyright (C) 2010 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.