PHPMyAdmin Import_Blacklist Variable Overwrite Vulnerability
BID:15761
Info
PHPMyAdmin Import_Blacklist Variable Overwrite Vulnerability
| Bugtraq ID: | 15761 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 07 2005 12:00AM |
| Updated: | Aug 15 2006 08:10PM |
| Credit: | Stefan Esser of the Hardened-PHP Project is credited with the discovery of this vulnerability. |
| Vulnerable: |
S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 phpMyAdmin phpMyAdmin 2.7 .0-beta1 phpMyAdmin phpMyAdmin 2.7 Gentoo Linux |
| Not Vulnerable: |
phpMyAdmin phpMyAdmin 2.7 -pl1 |
Discussion
PHPMyAdmin Import_Blacklist Variable Overwrite Vulnerability
phpMyAdmin is prone to a vulnerability that permits an attacker to overwrite global variables.
An attacker can exploit this issue to overwrite the global variables with arbitrary input. Through control of the global variables, the attacker may be able to include arbitrary remote and local files depending on the current PHP version. Various other attacks are also possible.
phpMyAdmin is prone to a vulnerability that permits an attacker to overwrite global variables.
An attacker can exploit this issue to overwrite the global variables with arbitrary input. Through control of the global variables, the attacker may be able to include arbitrary remote and local files depending on the current PHP version. Various other attacks are also possible.
Exploit / POC
PHPMyAdmin Import_Blacklist Variable Overwrite Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
PHPMyAdmin Import_Blacklist Variable Overwrite Vulnerability
Solution:
Gentoo has released advisory GLSA 200512-03 to address this and other issues. To obtain updates, execute the following commands:
emerge --sync
emerge --ask --oneshot --verbose ">=dev-db/phpmyadmin-2.7.0_p1"
SUSE Linux has released security advisory SUSE-SA:2006:004 addressing this and other issues. Please see the referenced advisory for further information.
The vendor has released an update addressing this issue:
phpMyAdmin phpMyAdmin 2.7
phpMyAdmin phpMyAdmin 2.7 .0-beta1
Solution:
Gentoo has released advisory GLSA 200512-03 to address this and other issues. To obtain updates, execute the following commands:
emerge --sync
emerge --ask --oneshot --verbose ">=dev-db/phpmyadmin-2.7.0_p1"
SUSE Linux has released security advisory SUSE-SA:2006:004 addressing this and other issues. Please see the referenced advisory for further information.
The vendor has released an update addressing this issue:
phpMyAdmin phpMyAdmin 2.7
-
phpMyAdmin phpMyAdmin-2.7.0-pl1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.7.0-pl1.tar .gz
phpMyAdmin phpMyAdmin 2.7 .0-beta1
-
phpMyAdmin phpMyAdmin-2.7.0-pl1.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.7.0-pl1.tar .gz
References
PHPMyAdmin Import_Blacklist Variable Overwrite Vulnerability
References:
References:
- Main Vendor Homepage (OWASP)
- phpMyAdmin 2.7.0-pl1 Release Notes (phpMyAdmin)
- phpMyAdmin Variable Overwrite Vulnerability (Hardened-PHP Project)