漏洞信息详情
phpMyAdmin远程命令执行漏洞
漏洞简介
phpMyAdmin 2.5.0至2.6.0-pl1版本的MIME转化系统(transformations/text_plain__external.inc.php)存在漏洞。远程攻击者借助未明向量中的shell元字符执行任意命令。
漏洞公告
Gentoo Linux has released advisory GLSA 200410-14 dealing with this issue. They have advised that all phpMyAdmin users should upgrade to the latest version: # emerge sync # emerge -pv ">=dev-db/phpmyadmin-2.6.0_p2" # emerge ">=dev-db/phpmyadmin-2.6.0_p2" Please see the referenced Gentoo advisory for more information. The vendor has released phpMyAdmin 2.6.0 pl2 to address this issue. phpMyAdmin phpMyAdmin 2.0
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
- phpMyAdmin phpMyAdmin 2.6.0-pl2 http://sourceforge.net/project/showfiles.php?group_id=23067&package_id =16462&release_id=274709
参考网址
来源: XF 名称: phpmyadmin-command-execution(17698) 链接:http://xforce.iss.net/xforce/xfdb/17698 来源: BID 名称: 11391 链接:http://www.securityfocus.com/bid/11391 来源: www.phpmyadmin.net 链接:http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2004-2 来源: GENTOO 名称: GLSA-200410-14 链接:http://www.gentoo.org/security/en/glsa/glsa-200410-14.xml 来源: SECTRACK 名称: 1011761 链接:http://securitytracker.com/alerts/2004/Oct/1011761.html 来源: SECUNIA 名称: 12859 链接:http://secunia.com/advisories/12859 来源: SECUNIA 名称: 12813 链接:http://secunia.com/advisories/12813 来源: FULLDISC 名称: 20041018: phpMyAdmin: Vulnerability in MIME-based transformation 链接:http://marc.theaimsgroup.com/?l=full-disclosure&m=109810251501643&w=2 来源: BUGTRAQ 名称: 20041018 phpMyAdmin: Vulnerability in MIME-based transformation 链接:http://marc.theaimsgroup.com/?l=bugtraq&m=109816584519779&w=2 来源: OSVDB 名称: 10715 链接:http://www.osvdb.org/10715
受影响实体
- Phpmyadmin Phpmyadmin:2.6.0_pl1<!--2000-1-1-->
- Phpmyadmin Phpmyadmin:2.5.7_pl1<!--2000-1-1-->
- Phpmyadmin Phpmyadmin:2.5.7<!--2000-1-1-->
- Phpmyadmin Phpmyadmin:2.5.5_rc2<!--2000-1-1-->
- Phpmyadmin Phpmyadmin:2.5.6_rc1<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...