PHPMyAdmin Local File Include Vulnerability
BID:15053
Info
PHPMyAdmin Local File Include Vulnerability
| Bugtraq ID: | 15053 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 10 2005 12:00AM |
| Updated: | Oct 10 2005 12:00AM |
| Credit: | Discovery is credited to Maksymilian Arciemowicz <[email protected]>. |
| Vulnerable: |
phpMyAdmin phpMyAdmin 2.6.4 -pl1 Gentoo dev-db/phpmyadmin 2.6.4 _p2 |
| Not Vulnerable: | |
Discussion
PHPMyAdmin Local File Include Vulnerability
phpMyAdmin is prone to a local file include vulnerability.
An attacker may leverage this issue to execute arbitrary server-side script code that resides on an affected computer with the privileges of the Web server process. This may potentially facilitate unauthorized access.
phpMyAdmin 2.6.4-pl1 is reported to be vulnerable. Other versions may be affected as well.
phpMyAdmin is prone to a local file include vulnerability.
An attacker may leverage this issue to execute arbitrary server-side script code that resides on an affected computer with the privileges of the Web server process. This may potentially facilitate unauthorized access.
phpMyAdmin 2.6.4-pl1 is reported to be vulnerable. Other versions may be affected as well.
Exploit / POC
PHPMyAdmin Local File Include Vulnerability
No exploit is required.
The following proof of concept is available:
No exploit is required.
The following proof of concept is available:
Solution / Fix
PHPMyAdmin Local File Include Vulnerability
Solution:
Gentoo advisory GLSA 200510-16 has been released to address this issue. Please see the referenced advisory for further details.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
The vendor has released version 2.6.4-pl3 of the application to address this issue; please see the references contained in this BID for more information.
phpMyAdmin phpMyAdmin 2.6.4 -pl1
Solution:
Gentoo advisory GLSA 200510-16 has been released to address this issue. Please see the referenced advisory for further details.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
The vendor has released version 2.6.4-pl3 of the application to address this issue; please see the references contained in this BID for more information.
phpMyAdmin phpMyAdmin 2.6.4 -pl1
-
phpMyAdmin phpMyAdmin-2.6.4-pl3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.4-pl3.tar .gz
References
PHPMyAdmin Local File Include Vulnerability
References:
References:
- Main Vendor Homepage (OWASP)
- phpMyAdmin Local File Inclusion Vulnerability (Stefan Esser [[email protected]])