PHPMyAdmin Plain Text Password Storage Vulnerability
BID:7965
Info
PHPMyAdmin Plain Text Password Storage Vulnerability
| Bugtraq ID: | 7965 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 18 2003 12:00AM |
| Updated: | Jun 18 2003 12:00AM |
| Credit: | Discovery of these vulnerabilities credited to Lorenzo Manuel Hernandez Garcia-Hierro <[email protected]>. |
| Vulnerable: |
phpMyAdmin phpMyAdmin 2.5.1 phpMyAdmin phpMyAdmin 2.5 .0 phpMyAdmin phpMyAdmin 2.4 .0 phpMyAdmin phpMyAdmin 2.3.2 phpMyAdmin phpMyAdmin 2.3.1 phpMyAdmin phpMyAdmin 2.2.6 phpMyAdmin phpMyAdmin 2.2.5 phpMyAdmin phpMyAdmin 2.2.4 phpMyAdmin phpMyAdmin 2.2.3 phpMyAdmin phpMyAdmin 2.2.2 phpMyAdmin phpMyAdmin 2.1 .2 phpMyAdmin phpMyAdmin 2.1 .1 phpMyAdmin phpMyAdmin 2.1 phpMyAdmin phpMyAdmin 2.0.5 phpMyAdmin phpMyAdmin 2.0.4 phpMyAdmin phpMyAdmin 2.0.3 phpMyAdmin phpMyAdmin 2.0.2 phpMyAdmin phpMyAdmin 2.0.1 phpMyAdmin phpMyAdmin 2.0 |
| Not Vulnerable: |
phpMyAdmin phpMyAdmin 2.5.2 |
Discussion
PHPMyAdmin Plain Text Password Storage Vulnerability
An issue has been reported for phpMyAdmin whereby passwords are stored in a plain text format. As a result, a malicious local user capable of accessing the cookie file may be capable of obtaining the users phpMyAdmin password. This issue could be exaggerated by the fact that the credentials may be used across multiple systems.
An issue has been reported for phpMyAdmin whereby passwords are stored in a plain text format. As a result, a malicious local user capable of accessing the cookie file may be capable of obtaining the users phpMyAdmin password. This issue could be exaggerated by the fact that the credentials may be used across multiple systems.