Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.800381
Categoría:Web application abuses
Título:phpMyAdmin 2.11.x < 2.11.9.4 / 3.0.x < 3.1.3 Multiple Vulnerabilities
Resumen:phpMyAdmin is prone to multiple vulnerabilities.
Descripción:Summary:
phpMyAdmin is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws are due to:

- BLOB streaming feature in 'bs_disp_as_mime_type.php' causes CRLF Injection
which lets the attacker inject arbitrary data in the HTTP headers through
the 'c_type' and 'file_type' parameters.

- XSS Vulnerability in 'display_export.lib.php' as its not sanitizing the
'pma_db_filename_template' parameter.

- Static code injection vulnerability in 'setup.php' which can be used to
inject PHP Codes.

- Filename 'bs_disp_as_mime_type.php' which is not sanitizing user supplied
inputs in the filename variable which causes directory traversal attacks.

Vulnerability Impact:
Successful exploitation will let the attacker cause XSS, Directory Traversal
attacks or can injection malicious PHP Codes to gain sensitive information about the remote host.

Affected Software/OS:
phpMyAdmin version 2.11.x to 2.11.9.4 and 3.0.x to 3.1.3.

Solution:
Upgrade to version 2.11.9.5 or 3.1.3.1 or later.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2009-1148
http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/branches/MAINT_3_1_3/phpMyAdmin/bs_disp_as_mime_type.php?r1=12303&r2=12302&pathrev=12303
http://secunia.com/advisories/34468
http://secunia.com/advisories/34642
SuSE Security Announcement: SUSE-SR:2009:008 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html
Common Vulnerability Exposure (CVE) ID: CVE-2009-1149
Common Vulnerability Exposure (CVE) ID: CVE-2009-1150
BugTraq ID: 34251
http://www.securityfocus.com/bid/34251
Debian Security Information: DSA-1824 (Google Search)
http://www.debian.org/security/2009/dsa-1824
http://security.gentoo.org/glsa/glsa-200906-03.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2009:115
http://secunia.com/advisories/34430
http://secunia.com/advisories/35585
http://secunia.com/advisories/35635
Common Vulnerability Exposure (CVE) ID: CVE-2009-1151
BugTraq ID: 34236
http://www.securityfocus.com/bid/34236
Bugtraq: 20090609 CVE-2009-1151: phpMyAdmin Remote Code Execution Proof of Concept (Google Search)
http://www.securityfocus.com/archive/1/504191/100/0/threaded
https://www.exploit-db.com/exploits/8921
http://labs.neohapsis.com/2009/04/06/about-cve-2009-1151/
http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/
CopyrightCopyright (C) 2009 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.