Go Back   Website Hosting - VPS Hosting - Domain Registration Ireland :: Blacknight > Technical Support > Security Notices
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 20-12-05, 08:07 AM
Administrator
Site Admin
 
Join Date: Aug 2003
Posts: 134
Default phpMyAdmin Cross-Site Request Forgery Vulnerability

http://secunia.com/advisories/18113/

Description:
lwang has discovered a vulnerability in phpMyAdmin, which can be exploited by malicious people to conduct cross-site request forgery attacks.

The vulnerability is caused due to the application allowing users to perform certain actions via HTTP GET requests without performing any validity checks to verify the user's request. This can e.g. be exploited to manipulate SQL queries by injecting arbitrary SQL code via the "checkprivs" or "hostname" parameter passed to "server_privileges.php".

The vulnerability has been confirmed in version 2.7.0-pl1. Other versions may also be affected.

Solution:
Do not browse untrusted web sites while being logged in to the management interface of phpMyAdmin.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
phpMyAdmin HTTP Response Splitting Vulnerability pkelly Security Notices 0 16-11-05 04:18 PM


All times are GMT. The time now is 07:21 AM.


VPS Hosting Web Hosting Ireland Blacknight Blog Blacknight Status

Powered by: vBulletin Version 3.6.8, Copyright ©2000 - 2008, Jelsoft Enterprises Limited.
Blacknight 2005 - 2008 | VPS Hosting

SEO by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17