漏洞信息详情
phpPgAdmin 路径遍历漏洞
漏洞简介
phpPgAdmin是一个应用软件。用于 postgresql 的首要基于 Web 的管理工具。
phpPgAdmin 4.2.1及其早期版本的libraries/lib.inc.php中存在目录遍历漏洞,当 register_globals被激活时,远程攻击者可以借助对index.php的_language参数中的一个..,读取任意文件。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Debian Linux 4.0 amd64
Debian phppgadmin_4.0.1-3.1etch1_all.deb
http://security.debian.org/pool/updates/main/p/phppgadmin/phppgadmin_4
.0.1-3.1etch1_all.deb
Debian Linux 4.0 ia-32
Debian phppgadmin_4.0.1-3.1etch1_all.deb
http://security.debian.org/pool/updates/main/p/phppgadmin/phppgadmin_4
.0.1-3.1etch1_all.deb
Debian Linux 4.0 arm
Debian phppgadmin_4.0.1-3.1etch1_all.deb
http://security.debian.org/pool/updates/main/p/phppgadmin/phppgadmin_4
.0.1-3.1etch1_all.deb
Debian Linux 4.0 hppa
Debian phppgadmin_4.0.1-3.1etch1_all.deb
http://security.debian.org/pool/updates/main/p/phppgadmin/phppgadmin_4
.0.1-3.1etch1_all.deb
Debian Linux 4.0 sparc
Debian phppgadmin_4.0.1-3.1etch1_all.deb
http://security.debian.org/pool/updates/main/p/phppgadmin/phppgadmin_4
.0.1-3.1etch1_all.deb
Debian Linux 4.0 s/390
Debian phppgadmin_4.0.1-3.1etch1_all.deb
http://security.debian.org/pool/updates/main/p/phppgadmin/phppgadmin_4
.0.1-3.1etch1_all.deb
Debian Linux 4.0 powerpc
Debian phppgadmin_4.0.1-3.1etch1_all.deb
http://security.debian.org/pool/updates/main/p/phppgadmin/phppgadmin_4
.0.1-3.1etch1_all.deb
Debian Linux 4.0 alpha
Debian phppgadmin_4.0.1-3.1etch1_all.deb
http://security.debian.org/pool/updates/main/p/phppgadmin/phppgadmin_4
.0.1-3.1etch1_all.deb
Debian Linux 4.0 m68k
Debian phppgadmin_4.0.1-3.1etch1_all.deb
http://security.debian.org/pool/updates/main/p/phppgadmin/phppgadmin_4
.0.1-3.1etch1_all.deb
Debian Linux 4.0
Debian phppgadmin_4.0.1-3.1etch1_all.deb
http://security.debian.org/pool/updates/main/p/phppgadmin/phppgadmin_4
.0.1-3.1etch1_all.deb
Debian Linux 4.0 mipsel
Debian phppgadmin_4.0.1-3.1etch1_all.deb
http://security.debian.org/pool/updates/main/p/phppgadmin/phppgadmin_4
.0.1-3.1etch1_all.deb
Debian Linux 4.0 ia-64
Debian phppgadmin_4.0.1-3.1etch1_all.deb
http://security.debian.org/pool/updates/main/p/phppgadmin/phppgadmin_4
.0.1-3.1etch1_all.deb
Debian Linux 4.0 mips
Debian phppgadmin_4.0.1-3.1etch1_all.deb
http://security.debian.org/pool/updates/main/p/phppgadmin/phppgadmin_4
.0.1-3.1etch1_all.deb
参考网址
来源: XF
名称: phppgadmin-index-file-include(47140)
链接:http://xforce.iss.net/xforce/xfdb/47140
来源: BID
名称: 32670
链接:http://www.securityfocus.com/bid/32670
来源: MILW0RM
名称: 7363
链接:http://www.milw0rm.com/exploits/7363
来源: DEBIAN
名称: DSA-1693
链接:http://www.debian.org/security/2008/dsa-1693
来源: SREASON
名称: 4737
链接:http://securityreason.com/securityalert/4737
来源: SECUNIA
名称: 33263
链接:http://secunia.com/advisories/33263
来源: SECUNIA
名称: 33014
链接:http://secunia.com/advisories/33014
来源: SUSE
名称: SUSE-SR:2009:004
链接:http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
受影响实体
- Phppgadmin Phppgadmin:4.2.1<!--2000-1-1-->
- Phppgadmin Phppgadmin:4.1.1<!--2000-1-1-->
- Phppgadmin Phppgadmin:3.5.3<!--2000-1-1-->
- Phppgadmin Phppgadmin:3.5.2<!--2000-1-1-->
- Phppgadmin Phppgadmin:3.5<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...