PHPMyAdmin Convcharset Cross-Site Scripting Vulnerability
BID:12982
Info
PHPMyAdmin Convcharset Cross-Site Scripting Vulnerability
| Bugtraq ID: | 12982 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-0992 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 03 2005 12:00AM |
| Updated: | Jan 12 2007 10:30PM |
| Credit: | Discovery is credited to Oriol Torrent Santiago <[email protected]>. |
| Vulnerable: |
phpMyAdmin phpMyAdmin 2.6.1 pl3 phpMyAdmin phpMyAdmin 2.6.1 pl1 phpMyAdmin phpMyAdmin 2.6.1 -rc1 phpMyAdmin phpMyAdmin 2.6.1 phpMyAdmin phpMyAdmin 2.6 .0pl3 phpMyAdmin phpMyAdmin 2.6 .0pl2 phpMyAdmin phpMyAdmin 2.6 .0pl1 phpMyAdmin phpMyAdmin 2.5.7 pl1 phpMyAdmin phpMyAdmin 2.5.7 phpMyAdmin phpMyAdmin 2.5.6 -rc1 phpMyAdmin phpMyAdmin 2.5.5 pl1 phpMyAdmin phpMyAdmin 2.5.5 -rc2 phpMyAdmin phpMyAdmin 2.5.5 -rc1 phpMyAdmin phpMyAdmin 2.5.5 phpMyAdmin phpMyAdmin 2.5.4 phpMyAdmin phpMyAdmin 2.5.3 phpMyAdmin phpMyAdmin 2.5.2 phpMyAdmin phpMyAdmin 2.5.1 phpMyAdmin phpMyAdmin 2.5 .0 phpMyAdmin phpMyAdmin 2.4 .0 phpMyAdmin phpMyAdmin 2.3.2 phpMyAdmin phpMyAdmin 2.3.1 phpMyAdmin phpMyAdmin 2.2.6 phpMyAdmin phpMyAdmin 2.2.5 phpMyAdmin phpMyAdmin 2.2.4 phpMyAdmin phpMyAdmin 2.2.3 phpMyAdmin phpMyAdmin 2.2.2 phpMyAdmin phpMyAdmin 2.2 rc3 phpMyAdmin phpMyAdmin 2.2 rc2 phpMyAdmin phpMyAdmin 2.2 rc1 phpMyAdmin phpMyAdmin 2.2 pre2 phpMyAdmin phpMyAdmin 2.2 pre1 phpMyAdmin phpMyAdmin 2.2 phpMyAdmin phpMyAdmin 2.1 .2 phpMyAdmin phpMyAdmin 2.1 .1 phpMyAdmin phpMyAdmin 2.1 phpMyAdmin phpMyAdmin 2.0.5 phpMyAdmin phpMyAdmin 2.0.4 phpMyAdmin phpMyAdmin 2.0.3 phpMyAdmin phpMyAdmin 2.0.2 phpMyAdmin phpMyAdmin 2.0.1 phpMyAdmin phpMyAdmin 2.0 |
| Not Vulnerable: |
phpMyAdmin phpMyAdmin 2.6.2 -rc1 |
Discussion
PHPMyAdmin Convcharset Cross-Site Scripting Vulnerability
phpMyAdmin is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input to the 'convcharset' parameter.
phpMyAdmin versions prior to 2.6.2-rc1 are affected by this issue.
phpMyAdmin is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input to the 'convcharset' parameter.
phpMyAdmin versions prior to 2.6.2-rc1 are affected by this issue.
Exploit / POC
PHPMyAdmin Convcharset Cross-Site Scripting Vulnerability
No exploit is required.
The following proof-of-concept URIs are available:
http://www.example.com/phpmyadmin/index.php?pma_username=&pma_password=&server=1&lang=en-iso-8859-1&convcharset=\"><script>alert(document.cookie)</script>
http://www.example.com/phpmyadmin/index.php?pma_username=&pma_password=&server=1&lang=en-iso-8859-1&convcharset=\"><h1>XSS</h1>
No exploit is required.
The following proof-of-concept URIs are available:
http://www.example.com/phpmyadmin/index.php?pma_username=&pma_password=&server=1&lang=en-iso-8859-1&convcharset=\"><script>alert(document.cookie)</script>
http://www.example.com/phpmyadmin/index.php?pma_username=&pma_password=&server=1&lang=en-iso-8859-1&convcharset=\"><h1>XSS</h1>
Solution / Fix
PHPMyAdmin Convcharset Cross-Site Scripting Vulnerability
Solution:
Please see the referenced advisories for more information.
phpMyAdmin phpMyAdmin 2.0
phpMyAdmin phpMyAdmin 2.0.1
phpMyAdmin phpMyAdmin 2.0.2
phpMyAdmin phpMyAdmin 2.0.3
phpMyAdmin phpMyAdmin 2.0.4
phpMyAdmin phpMyAdmin 2.0.5
phpMyAdmin phpMyAdmin 2.1 .2
phpMyAdmin phpMyAdmin 2.1
phpMyAdmin phpMyAdmin 2.1 .1
phpMyAdmin phpMyAdmin 2.2 pre1
phpMyAdmin phpMyAdmin 2.2 rc3
phpMyAdmin phpMyAdmin 2.2 pre2
phpMyAdmin phpMyAdmin 2.2 rc2
phpMyAdmin phpMyAdmin 2.2
phpMyAdmin phpMyAdmin 2.2 rc1
phpMyAdmin phpMyAdmin 2.2.2
phpMyAdmin phpMyAdmin 2.2.3
phpMyAdmin phpMyAdmin 2.2.4
phpMyAdmin phpMyAdmin 2.2.5
phpMyAdmin phpMyAdmin 2.2.6
phpMyAdmin phpMyAdmin 2.3.1
phpMyAdmin phpMyAdmin 2.3.2
phpMyAdmin phpMyAdmin 2.4 .0
phpMyAdmin phpMyAdmin 2.5 .0
phpMyAdmin phpMyAdmin 2.5.1
phpMyAdmin phpMyAdmin 2.5.2
phpMyAdmin phpMyAdmin 2.5.4
phpMyAdmin phpMyAdmin 2.5.5 -rc2
phpMyAdmin phpMyAdmin 2.5.5 -rc1
phpMyAdmin phpMyAdmin 2.5.5
phpMyAdmin phpMyAdmin 2.5.5 pl1
phpMyAdmin phpMyAdmin 2.5.6 -rc1
phpMyAdmin phpMyAdmin 2.5.7
phpMyAdmin phpMyAdmin 2.5.7 pl1
phpMyAdmin phpMyAdmin 2.6 .0pl2
phpMyAdmin phpMyAdmin 2.6 .0pl1
phpMyAdmin phpMyAdmin 2.6 .0pl3
phpMyAdmin phpMyAdmin 2.6.1 pl3
phpMyAdmin phpMyAdmin 2.6.1 pl1
phpMyAdmin phpMyAdmin 2.6.1 -rc1
phpMyAdmin phpMyAdmin 2.6.1
Solution:
Please see the referenced advisories for more information.
phpMyAdmin phpMyAdmin 2.0
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.0.1
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.0.2
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.0.3
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.0.4
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.0.5
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.1 .2
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.1
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.1 .1
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.2 pre1
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.2 rc3
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.2 pre2
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.2 rc2
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.2
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.2 rc1
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.2.2
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.2.3
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.2.4
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.2.5
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.2.6
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.3.1
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.3.2
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.4 .0
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.5 .0
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.5.1
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.5.2
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.5.4
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.5.5 -rc2
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.5.5 -rc1
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.5.5
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.5.5 pl1
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.5.6 -rc1
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.5.7
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.5.7 pl1
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.6 .0pl2
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.6 .0pl1
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.6 .0pl3
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.6.1 pl3
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.6.1 pl1
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.6.1 -rc1
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
phpMyAdmin phpMyAdmin 2.6.1
-
phpMyAdmin phpMyAdmin-2.6.2-rc1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.2-rc1.tar .gz?download
References
PHPMyAdmin Convcharset Cross-Site Scripting Vulnerability
References:
References:
- Main Vendor Homepage (OWASP)
- phpMyAdmin Cross-site Scripting Vulnerability (Oriol Torrent Santiago < [email protected] >)
- PMASA-2005-3 - Cross-Site Scripting vulnerability (phpMyAdmin)
- xss in phpmyadmin <= 2.8.1 ([email protected])