PHPPGAdmin Include File Arbitrary Command Execution Vulnerability
BID:2640
Info
PHPPGAdmin Include File Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 2640 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-0479 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 23 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | This vulnerability was announced to Bugtraq in a Secure Reality Security Advisory posted on April 24, 2001. |
| Vulnerable: |
Phppgadmin Project Phppgadmin 2.2.1 pl1 Phppgadmin Project Phppgadmin 2.2.1 Phppgadmin Project Phppgadmin 2.2 |
| Not Vulnerable: |
Phppgadmin Project Phppgadmin 2.3 |
Discussion
PHPPGAdmin Include File Arbitrary Command Execution Vulnerability
phpPgAdmin is a freely available, open source software package developed and maintained by the phpPgAdmin Development Team. phpPgAdmin is designed as a user friendly, graphical frontend to PostgreSQL database administration.
A problem with the software package could allow arbitrary file inclusion. Due to the insufficient validation of input by the sql.php script, it is possible to supply an include file to the sql.php script, which will result in the code in the include file being executed. A remote user with knowledge of files on the local host, or the ability to upload an include file, may specify the file to be included in execution, which could result in code supplied include file being executed.
Therefore, it is possible for a remote user to supply an include file to the sql.php script, and execute arbitrary code.
phpPgAdmin is a freely available, open source software package developed and maintained by the phpPgAdmin Development Team. phpPgAdmin is designed as a user friendly, graphical frontend to PostgreSQL database administration.
A problem with the software package could allow arbitrary file inclusion. Due to the insufficient validation of input by the sql.php script, it is possible to supply an include file to the sql.php script, which will result in the code in the include file being executed. A remote user with knowledge of files on the local host, or the ability to upload an include file, may specify the file to be included in execution, which could result in code supplied include file being executed.
Therefore, it is possible for a remote user to supply an include file to the sql.php script, and execute arbitrary code.
Exploit / POC
PHPPGAdmin Include File Arbitrary Command Execution Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
PHPPGAdmin Include File Arbitrary Command Execution Vulnerability
Solution:
Patches available:
Phppgadmin Project Phppgadmin 2.2
Phppgadmin Project Phppgadmin 2.2.1 pl1
Phppgadmin Project Phppgadmin 2.2.1
Solution:
Patches available:
Phppgadmin Project Phppgadmin 2.2
-
phpPgAdmin phpPgAdmin_2-3.tar.gz
ftp://ftp.greatbridge.org/pub/phppgadmin/stable/phpPgAdmin_2-3.tar.gz -
Secure Reality 2.2.1 phpPgAdmin-SecureReality.diff
http://www.securereality.com.au/patches/phpPgAdmin-SecureReality.diff
Phppgadmin Project Phppgadmin 2.2.1 pl1
-
phpPgAdmin phpPgAdmin_2-3.tar.gz
ftp://ftp.greatbridge.org/pub/phppgadmin/stable/phpPgAdmin_2-3.tar.gz -
Secure Reality 2.2.1 phpPgAdmin-SecureReality.diff
http://www.securereality.com.au/patches/phpPgAdmin-SecureReality.diff
Phppgadmin Project Phppgadmin 2.2.1
-
phpPgAdmin phpPgAdmin_2-3.tar.gz
ftp://ftp.greatbridge.org/pub/phppgadmin/stable/phpPgAdmin_2-3.tar.gz -
Secure Reality 2.2.1 phpPgAdmin-SecureReality.diff
http://www.securereality.com.au/patches/phpPgAdmin-SecureReality.diff
References
PHPPGAdmin Include File Arbitrary Command Execution Vulnerability
References:
References: