xMySQLadmin Insecure Temporary File Creation Vulnerability
BID:13913
Info
xMySQLadmin Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 13913 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 25 2005 12:00AM |
| Updated: | May 25 2005 12:00AM |
| Credit: | Eric Romang is credited with the discovery of this vulnerability. |
| Vulnerable: |
xMySQLadmin xMySQLadmin 1.0 |
| Not Vulnerable: | |
Discussion
xMySQLadmin Insecure Temporary File Creation Vulnerability
xMySQLadmin is prone to an insecure temporary file creation vulnerability.
This issue is due to a design error that causes a file to be insecurely created.
An attacker may leverage this issue to delete or corrupt arbitrary files with the privileges of an unsuspecting user that activates the affected application.
xMySQLadmin is prone to an insecure temporary file creation vulnerability.
This issue is due to a design error that causes a file to be insecurely created.
An attacker may leverage this issue to delete or corrupt arbitrary files with the privileges of an unsuspecting user that activates the affected application.
Exploit / POC
xMySQLadmin Insecure Temporary File Creation Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
xMySQLadmin Insecure Temporary File Creation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
xMySQLadmin Insecure Temporary File Creation Vulnerability
References:
References:
- dev-db/xmysqladmin <= 1.0 insecure temporary file creation && maybe more (Gentoo - Bugzilla)
- xmysqladmin insecure temporary file creation (ZATAZ Audits
)