phpPgAdmin Included File Arbitrary Command Execution Vulnerability
BID:2967
Info
phpPgAdmin Included File Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 2967 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 02 2001 12:00AM |
| Updated: | Mar 19 2015 09:10AM |
| Credit: | Published in a Secure Reality Security Advisory on July 2, 2001. |
| Vulnerable: |
phpPgAdmin phpPgAdmin 2.2.1 pl1 phpPgAdmin phpPgAdmin 2.2.1 phpPgAdmin phpPgAdmin 2.2 |
| Not Vulnerable: |
phpPgAdmin phpPgAdmin 2.3 |
Discussion
phpPgAdmin Included File Arbitrary Command Execution Vulnerability
phpPgAdmin is a freely available tool that provides a WWW interface for handling PostgreSQL adminstrative tasks. It is derived from phpMyAdmin, which is used for MySQL administrative tasks.
An input validation error exists in phpPgAdmin that could allow remote users to cause arbitrary files to be included and loaded by the PHP interpreter at runtime. This may result in the disclosure of sensitive information or the execution of arbitrary code on a host running the software.
phpPgAdmin is a freely available tool that provides a WWW interface for handling PostgreSQL adminstrative tasks. It is derived from phpMyAdmin, which is used for MySQL administrative tasks.
An input validation error exists in phpPgAdmin that could allow remote users to cause arbitrary files to be included and loaded by the PHP interpreter at runtime. This may result in the disclosure of sensitive information or the execution of arbitrary code on a host running the software.
Exploit / POC
phpPgAdmin Included File Arbitrary Command Execution Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
phpPgAdmin Included File Arbitrary Command Execution Vulnerability
Solution:
This issue is resolved in versions 2.3 and higher of phpPgAdmin:
phpPgAdmin phpPgAdmin 2.2
phpPgAdmin phpPgAdmin 2.2.1 pl1
phpPgAdmin phpPgAdmin 2.2.1
Solution:
This issue is resolved in versions 2.3 and higher of phpPgAdmin:
phpPgAdmin phpPgAdmin 2.2
-
phpPgAdmin phpPgAdmin_2-3.tar.gz
ftp://ftp.greatbridge.org/pub/phppgadmin/stable/phpPgAdmin_2-3.tar.gz -
Secure Reality 2.2.1 phpPgAdmin-SecureReality.diff
http://www.securereality.com.au/patches/phpPgAdmin-SecureReality.diff
phpPgAdmin phpPgAdmin 2.2.1 pl1
-
phpPgAdmin phpPgAdmin_2-3.tar.gz
ftp://ftp.greatbridge.org/pub/phppgadmin/stable/phpPgAdmin_2-3.tar.gz -
Secure Reality 2.2.1 phpPgAdmin-SecureReality.diff
http://www.securereality.com.au/patches/phpPgAdmin-SecureReality.diff
phpPgAdmin phpPgAdmin 2.2.1
-
phpPgAdmin phpPgAdmin_2-3.tar.gz
ftp://ftp.greatbridge.org/pub/phppgadmin/stable/phpPgAdmin_2-3.tar.gz -
Secure Reality 2.2.1 phpPgAdmin-SecureReality.diff
http://www.securereality.com.au/patches/phpPgAdmin-SecureReality.diff
References
phpPgAdmin Included File Arbitrary Command Execution Vulnerability
References:
References: