![]() |
Inicial ▼ Bookkeeping
Online ▼ Auditorias ▼
DNS
Administrado ▼
Acerca de DNS
Ordenar/Renovar
Preguntas Frecuentes
AUP
Dynamic DNS Clients
Configurar Dominios Dynamic DNS Update Password Monitoreo
de Redes ▼
Enterprise
Avanzado
Estándarr
Prueba
Preguntas Frecuentes
Resumen de Precio/Funciones
Ordenar
Muestras
Configure/Status Alert Profiles | ||
ID de Prueba: | 1.3.6.1.4.1.25623.1.0.66719 |
Categoría: | Mandrake Local Security Checks |
Título: | Mandriva Security Advisory MDVSA-2010:018 (phpMyAdmin) |
Resumen: | NOSUMMARY |
Descripción: | Description: The remote host is missing an update to phpMyAdmin announced via advisory MDVSA-2010:018. Multiple vulnerabilities has been found and corrected in phpMyAdmin: libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 creates a temporary directory with 0777 permissions, which has unknown impact and attack vectors (CVE-2008-7251). libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and attack vectors (CVE-2008-7252). scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors (CVE-2009-4605). This update provides phpMyAdmin 2.11.10, which is not vulnerable to these issues. Affected: Corporate 4.0 Solution: To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you. https://secure1.securityspace.com/smysecure/catid.html?in=MDVSA-2010:018 http://www.phpmyadmin.net/home_page/security/PMASA-2010-1.php http://www.phpmyadmin.net/home_page/security/PMASA-2010-2.php http://www.phpmyadmin.net/home_page/security/PMASA-2010-3.php Risk factor : Critical CVSS Score: 10.0 |
Referencia Cruzada: |
Common Vulnerability Exposure (CVE) ID: CVE-2008-7251 BugTraq ID: 37826 http://www.securityfocus.com/bid/37826 Debian Security Information: DSA-2034 (Google Search) http://www.debian.org/security/2010/dsa-2034 http://secunia.com/advisories/38211 http://secunia.com/advisories/39503 SuSE Security Announcement: SUSE-SR:2010:001 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.html http://www.vupen.com/english/advisories/2010/0910 Common Vulnerability Exposure (CVE) ID: CVE-2008-7252 Common Vulnerability Exposure (CVE) ID: CVE-2009-4605 |
Copyright | Copyright (c) 2010 E-Soft Inc. http://www.securityspace.com |
Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |