phpMyAdmin Multiple Input Validation Vulnerabilities
BID:10629
Info
phpMyAdmin Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 10629 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 29 2004 12:00AM |
| Updated: | Jun 29 2004 12:00AM |
| Credit: | Discovery of these vulnerabilities is credited to Nasir Simbolon <[email protected]>. |
| Vulnerable: |
phpMyAdmin phpMyAdmin 2.5.7 phpMyAdmin phpMyAdmin 2.5.6 -rc1 phpMyAdmin phpMyAdmin 2.5.5 pl1 phpMyAdmin phpMyAdmin 2.5.5 -rc2 phpMyAdmin phpMyAdmin 2.5.5 -rc1 phpMyAdmin phpMyAdmin 2.5.5 phpMyAdmin phpMyAdmin 2.5.4 phpMyAdmin phpMyAdmin 2.5.2 phpMyAdmin phpMyAdmin 2.5.1 Gentoo Linux 1.4 _rc3 Gentoo Linux 1.4 _rc2 Gentoo Linux 1.4 _rc1 Gentoo Linux 1.4 Gentoo Linux 1.2 Gentoo Linux 1.1 a Gentoo Linux 0.7 Gentoo Linux 0.5 |
| Not Vulnerable: |
phpMyAdmin phpMyAdmin 2.5.7 pl1 |
Discussion
phpMyAdmin Multiple Input Validation Vulnerabilities
phpMyAdmin is prone to multiple vulnerabilities. The issues result from insufficient sanitization of user-supplied data. The following specific issues can affect the application:
It is reported that a malicious attacker can add arbitrary servers to phpMyAdmin. By constructing a URI request for the phpMyAdmin 'left.php' script an attacker may specify and add an arbitrary SQL server.
A remote attacker may exploit this vulnerability to replace server configurations and as a result introduce a malicious SQL server into the phpMyAdmin controlled server list.
phpMyAdmin is reported prone to a remote PHP code execution vulnerability. It is reported that a malicious database table name beginning with "'" will escape the quotes in a PHP eval() statement and will thereby permit an attacker to execute arbitrary PHP code.
phpMyAdmin is prone to multiple vulnerabilities. The issues result from insufficient sanitization of user-supplied data. The following specific issues can affect the application:
It is reported that a malicious attacker can add arbitrary servers to phpMyAdmin. By constructing a URI request for the phpMyAdmin 'left.php' script an attacker may specify and add an arbitrary SQL server.
A remote attacker may exploit this vulnerability to replace server configurations and as a result introduce a malicious SQL server into the phpMyAdmin controlled server list.
phpMyAdmin is reported prone to a remote PHP code execution vulnerability. It is reported that a malicious database table name beginning with "'" will escape the quotes in a PHP eval() statement and will thereby permit an attacker to execute arbitrary PHP code.
Exploit / POC
phpMyAdmin Multiple Input Validation Vulnerabilities
The following exploit server is available:
The following exploit server is available:
Solution / Fix
phpMyAdmin Multiple Input Validation Vulnerabilities
Solution:
The vendor has released version 2.5.7, patch level 1 addressing this vulnerability. Users of affected packages are urged to upgrade.
Gentoo has released an advisory (GLSA 200407-22) and an updated eBuild to address the issues that are described in this BID. Gentoo users are advised to perform the following actions as a superuser in order to apply appropriate fixes.
emerge sync
emerge -pv ">=dev-db/phpmyadmin-2.5.7_p1"
emerge ">=dev-db/phpmyadmin-2.5.7_p1"
phpMyAdmin phpMyAdmin 2.5.1
phpMyAdmin phpMyAdmin 2.5.2
phpMyAdmin phpMyAdmin 2.5.4
phpMyAdmin phpMyAdmin 2.5.5 -rc2
phpMyAdmin phpMyAdmin 2.5.5 pl1
phpMyAdmin phpMyAdmin 2.5.5
phpMyAdmin phpMyAdmin 2.5.5 -rc1
phpMyAdmin phpMyAdmin 2.5.6 -rc1
phpMyAdmin phpMyAdmin 2.5.7
Solution:
The vendor has released version 2.5.7, patch level 1 addressing this vulnerability. Users of affected packages are urged to upgrade.
Gentoo has released an advisory (GLSA 200407-22) and an updated eBuild to address the issues that are described in this BID. Gentoo users are advised to perform the following actions as a superuser in order to apply appropriate fixes.
emerge sync
emerge -pv ">=dev-db/phpmyadmin-2.5.7_p1"
emerge ">=dev-db/phpmyadmin-2.5.7_p1"
phpMyAdmin phpMyAdmin 2.5.1
-
phpMyAdmin phpMyAdmin-2.5.7-pl1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.5.7-pl1.tar .gz?download
phpMyAdmin phpMyAdmin 2.5.2
-
phpMyAdmin phpMyAdmin-2.5.7-pl1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.5.7-pl1.tar .gz?download
phpMyAdmin phpMyAdmin 2.5.4
-
phpMyAdmin phpMyAdmin-2.5.7-pl1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.5.7-pl1.tar .gz?download
phpMyAdmin phpMyAdmin 2.5.5 -rc2
-
phpMyAdmin phpMyAdmin-2.5.7-pl1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.5.7-pl1.tar .gz?download
phpMyAdmin phpMyAdmin 2.5.5 pl1
-
phpMyAdmin phpMyAdmin-2.5.7-pl1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.5.7-pl1.tar .gz?download
phpMyAdmin phpMyAdmin 2.5.5
-
phpMyAdmin phpMyAdmin-2.5.7-pl1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.5.7-pl1.tar .gz?download
phpMyAdmin phpMyAdmin 2.5.5 -rc1
-
phpMyAdmin phpMyAdmin-2.5.7-pl1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.5.7-pl1.tar .gz?download
phpMyAdmin phpMyAdmin 2.5.6 -rc1
-
phpMyAdmin phpMyAdmin-2.5.7-pl1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.5.7-pl1.tar .gz?download
phpMyAdmin phpMyAdmin 2.5.7
-
phpMyAdmin phpMyAdmin-2.5.7-pl1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.5.7-pl1.tar .gz?download
References
phpMyAdmin Multiple Input Validation Vulnerabilities
References:
References:
- Main Vendor Homepage (OWASP)
- php codes injection in phpMyAdmin version 2.5.7. (Nasir Simbolon
) - Re: php codes injection in phpMyAdmin version 2.5.7. (Marc Delisle
) - Re: php codes injection in phpMyAdmin version 2.5.7. (Marc Delisle
)