![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.64024 |
Category: | Mandrake Local Security Checks |
Title: | Mandrake Security Advisory MDVSA-2009:115 (phpMyAdmin) |
Summary: | The remote host is missing an update to phpMyAdmin;announced via advisory MDVSA-2009:115. |
Description: | Summary: The remote host is missing an update to phpMyAdmin announced via advisory MDVSA-2009:115. Vulnerability Insight: Multiple vulnerabilities has been identified and corrected in phpMyAdmin: Multiple cross-site scripting (XSS) vulnerabilities in the export page (display_export.lib.php) in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allow remote attackers to inject arbitrary web script or HTML via the pma_db_filename_template cookie (CVE-2009-1150). Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action (CVE-2009-1151). This update provides phpMyAdmin 2.11.9.5, which is not vulnerable to these issues. Affected: Corporate 4.0 Solution: To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you. CVSS Score: 7.5 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2009-1150 BugTraq ID: 34251 http://www.securityfocus.com/bid/34251 Debian Security Information: DSA-1824 (Google Search) http://www.debian.org/security/2009/dsa-1824 http://security.gentoo.org/glsa/glsa-200906-03.xml http://www.mandriva.com/security/advisories?name=MDVSA-2009:115 http://secunia.com/advisories/34430 http://secunia.com/advisories/34642 http://secunia.com/advisories/35585 http://secunia.com/advisories/35635 SuSE Security Announcement: SUSE-SR:2009:008 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html Common Vulnerability Exposure (CVE) ID: CVE-2009-1151 BugTraq ID: 34236 http://www.securityfocus.com/bid/34236 Bugtraq: 20090609 CVE-2009-1151: phpMyAdmin Remote Code Execution Proof of Concept (Google Search) http://www.securityfocus.com/archive/1/504191/100/0/threaded https://www.exploit-db.com/exploits/8921 http://labs.neohapsis.com/2009/04/06/about-cve-2009-1151/ http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/ |
Copyright | Copyright (C) 2009 E-Soft Inc. |
This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |