PHPMyAdmin Multiple Cross-Site Scripting Vulnerabilities
BID:17390
Info
PHPMyAdmin Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 17390 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-1678 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 06 2006 12:00AM |
| Updated: | Jan 12 2007 10:30PM |
| Credit: | The vendor credits Toni Koivunen of CERT-FI with the discovery of these vulnerabilities. |
| Vulnerable: |
S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 phpMyAdmin phpMyAdmin 2.8 .1 phpMyAdmin phpMyAdmin 2.7 .0-beta1 phpMyAdmin phpMyAdmin 2.7 -pl1 phpMyAdmin phpMyAdmin 2.7 phpMyAdmin phpMyAdmin 2.6.4 -rc1 phpMyAdmin phpMyAdmin 2.6.4 -pl4 phpMyAdmin phpMyAdmin 2.6.4 -pl3 phpMyAdmin phpMyAdmin 2.6.4 -pl1 phpMyAdmin phpMyAdmin 2.6.3 -pl1 phpMyAdmin phpMyAdmin 2.6.2 -rc1 phpMyAdmin phpMyAdmin 2.6.2 phpMyAdmin phpMyAdmin 2.6.1 pl3 phpMyAdmin phpMyAdmin 2.6.1 pl1 phpMyAdmin phpMyAdmin 2.6.1 -rc1 phpMyAdmin phpMyAdmin 2.6.1 phpMyAdmin phpMyAdmin 2.6 .0pl3 phpMyAdmin phpMyAdmin 2.6 .0pl2 phpMyAdmin phpMyAdmin 2.6 .0pl1 phpMyAdmin phpMyAdmin 2.5.7 pl1 phpMyAdmin phpMyAdmin 2.5.7 phpMyAdmin phpMyAdmin 2.5.6 -rc1 phpMyAdmin phpMyAdmin 2.5.5 pl1 phpMyAdmin phpMyAdmin 2.5.5 -rc2 phpMyAdmin phpMyAdmin 2.5.5 -rc1 phpMyAdmin phpMyAdmin 2.5.5 phpMyAdmin phpMyAdmin 2.5.4 phpMyAdmin phpMyAdmin 2.5.3 phpMyAdmin phpMyAdmin 2.5.2 phpMyAdmin phpMyAdmin 2.5.1 phpMyAdmin phpMyAdmin 2.5 .0 phpMyAdmin phpMyAdmin 2.4 .0 phpMyAdmin phpMyAdmin 2.3.2 phpMyAdmin phpMyAdmin 2.3.1 phpMyAdmin phpMyAdmin 2.2.6 phpMyAdmin phpMyAdmin 2.2.5 phpMyAdmin phpMyAdmin 2.2.4 phpMyAdmin phpMyAdmin 2.2.3 phpMyAdmin phpMyAdmin 2.2.2 phpMyAdmin phpMyAdmin 2.2 rc3 phpMyAdmin phpMyAdmin 2.2 rc2 phpMyAdmin phpMyAdmin 2.2 rc1 phpMyAdmin phpMyAdmin 2.2 pre2 phpMyAdmin phpMyAdmin 2.2 pre1 phpMyAdmin phpMyAdmin 2.2 phpMyAdmin phpMyAdmin 2.1 .2 phpMyAdmin phpMyAdmin 2.1 .1 phpMyAdmin phpMyAdmin 2.1 phpMyAdmin phpMyAdmin 2.0.5 phpMyAdmin phpMyAdmin 2.0.4 phpMyAdmin phpMyAdmin 2.0.3 phpMyAdmin phpMyAdmin 2.0.2 phpMyAdmin phpMyAdmin 2.0.1 phpMyAdmin phpMyAdmin 2.0 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
phpMyAdmin phpMyAdmin 2.8 .3 |
Discussion
PHPMyAdmin Multiple Cross-Site Scripting Vulnerabilities
phpMyAdmin is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
These issues may be related to BID 17142 (PHPMyAdmin Set_Theme Cross-Site Scripting Vulnerability).
phpMyAdmin is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
These issues may be related to BID 17142 (PHPMyAdmin Set_Theme Cross-Site Scripting Vulnerability).
Exploit / POC
PHPMyAdmin Multiple Cross-Site Scripting Vulnerabilities
This issue can be exploited through a web client.
This issue can be exploited through a web client.
Solution / Fix
PHPMyAdmin Multiple Cross-Site Scripting Vulnerabilities
Solution:
The vendor has released an update to address these issues. Please see the referenced vendor advisory for details.
phpMyAdmin phpMyAdmin 2.0
phpMyAdmin phpMyAdmin 2.0.1
phpMyAdmin phpMyAdmin 2.0.2
phpMyAdmin phpMyAdmin 2.0.3
phpMyAdmin phpMyAdmin 2.0.4
phpMyAdmin phpMyAdmin 2.0.5
phpMyAdmin phpMyAdmin 2.1 .2
phpMyAdmin phpMyAdmin 2.1
phpMyAdmin phpMyAdmin 2.1 .1
phpMyAdmin phpMyAdmin 2.2 pre1
phpMyAdmin phpMyAdmin 2.2 rc3
phpMyAdmin phpMyAdmin 2.2 pre2
phpMyAdmin phpMyAdmin 2.2 rc2
phpMyAdmin phpMyAdmin 2.2
phpMyAdmin phpMyAdmin 2.2 rc1
phpMyAdmin phpMyAdmin 2.2.2
phpMyAdmin phpMyAdmin 2.2.3
phpMyAdmin phpMyAdmin 2.2.4
phpMyAdmin phpMyAdmin 2.2.5
phpMyAdmin phpMyAdmin 2.2.6
phpMyAdmin phpMyAdmin 2.3.1
phpMyAdmin phpMyAdmin 2.3.2
phpMyAdmin phpMyAdmin 2.4 .0
phpMyAdmin phpMyAdmin 2.5 .0
phpMyAdmin phpMyAdmin 2.5.1
phpMyAdmin phpMyAdmin 2.5.2
phpMyAdmin phpMyAdmin 2.5.3
phpMyAdmin phpMyAdmin 2.5.4
phpMyAdmin phpMyAdmin 2.5.5
phpMyAdmin phpMyAdmin 2.5.5 pl1
phpMyAdmin phpMyAdmin 2.5.5 -rc2
phpMyAdmin phpMyAdmin 2.5.5 -rc1
phpMyAdmin phpMyAdmin 2.5.6 -rc1
phpMyAdmin phpMyAdmin 2.5.7
phpMyAdmin phpMyAdmin 2.5.7 pl1
phpMyAdmin phpMyAdmin 2.6 .0pl2
phpMyAdmin phpMyAdmin 2.6 .0pl3
phpMyAdmin phpMyAdmin 2.6 .0pl1
phpMyAdmin phpMyAdmin 2.6.1 pl3
phpMyAdmin phpMyAdmin 2.6.1 pl1
phpMyAdmin phpMyAdmin 2.6.1 -rc1
phpMyAdmin phpMyAdmin 2.6.1
phpMyAdmin phpMyAdmin 2.6.2
phpMyAdmin phpMyAdmin 2.6.2 -rc1
phpMyAdmin phpMyAdmin 2.6.3 -pl1
phpMyAdmin phpMyAdmin 2.6.4 -pl1
phpMyAdmin phpMyAdmin 2.6.4 -pl4
phpMyAdmin phpMyAdmin 2.6.4 -pl3
phpMyAdmin phpMyAdmin 2.6.4 -rc1
phpMyAdmin phpMyAdmin 2.7 -pl1
phpMyAdmin phpMyAdmin 2.7 .0-beta1
phpMyAdmin phpMyAdmin 2.7
phpMyAdmin phpMyAdmin 2.8 .1
Solution:
The vendor has released an update to address these issues. Please see the referenced vendor advisory for details.
phpMyAdmin phpMyAdmin 2.0
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.0.1
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.0.2
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.0.3
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.0.4
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.0.5
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.1 .2
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.1
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.1 .1
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.2 pre1
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.2 rc3
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.2 pre2
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.2 rc2
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.2
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.2 rc1
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.2.2
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.2.3
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.2.4
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.2.5
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.2.6
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.3.1
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.3.2
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.4 .0
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.5 .0
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.5.1
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.5.2
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.5.3
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.5.4
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.5.5
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.5.5 pl1
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.5.5 -rc2
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.5.5 -rc1
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.5.6 -rc1
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.5.7
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.5.7 pl1
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.6 .0pl2
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.6 .0pl3
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.6 .0pl1
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.6.1 pl3
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.6.1 pl1
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.6.1 -rc1
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.6.1
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.6.2
-
Debian phpmyadmin_2.6.2-3sarge2_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/p/phpmyadmin/phpmyadmin_2 .6.2-3sarge2_all.deb -
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.6.2 -rc1
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.6.3 -pl1
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.6.4 -pl1
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.6.4 -pl4
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.6.4 -pl3
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.6.4 -rc1
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.7 -pl1
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.7 .0-beta1
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.7
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
phpMyAdmin phpMyAdmin 2.8 .1
-
phpMyAdmin phpMyAdmin-2.8.0.3.tar.gz
http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.0.3.tar.g z
References
PHPMyAdmin Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- Main Vendor Homepage (OWASP)
- phpMyAdmin security announcement PMASA-2006-1 (phpMyAdmin)