漏洞信息详情
phpMyAdmin多个跨站脚本攻击漏洞
漏洞简介
phpMyAdmin是用PHP编写的工具,用于通过WEB管理MySQL。
phpMyAdmin 2.11.10.1之前的2.11.x版本和3.3.5.1之前的3.x版本中存在多个跨站脚本攻击(XSS)漏洞。远程攻击者可以借助相关向量注入任意web脚本或HTML。相关向量有(1)db_search.php,(2)db_sql.php,(3)db_structure.php,(4)js/messages.php,(5)libraries/common.lib.php,(6)libraries/database_interface.lib.php,(7)libraries/dbi/mysql.dbi.lib.php,(8)libraries/dbi/mysqli.dbi.lib.php,(9)libraries/db_info.inc.php,(10)libraries/sanitizing.lib.php,(11)libraries/sqlparser.lib.php,(12)server_databases.php,(13)server_privileges.php,(14)setup/config.php,(15)sql.php,(16)tbl_replace.php和(17)tbl_sql.php。
漏洞公告
目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接:
http://www.phpmyadmin.net/home_page/security/PMASA-2010-5.php
参考网址
来源: BID
名称: 42584
链接:http://www.securityfocus.com/bid/42584
来源: www.phpmyadmin.net
链接:http://www.phpmyadmin.net/home_page/security/PMASA-2010-5.php
来源: bugzilla.redhat.com
链接:https://bugzilla.redhat.com/show_bug.cgi?id=625877
来源: MISC
链接:http://yehg.net/lab/pr0js/advisories/phpmyadmin/%5Bphpmyadmin-3.3.5%5D_cross_site_scripting%28XSS%29
来源: SECUNIA
名称: 41000
链接:http://secunia.com/advisories/41000
来源: FEDORA
名称: FEDORA-2010-13258
链接:http://lists.fedoraproject.org/pipermail/package-announce/2010-August/045997.html
来源: FEDORA
名称: FEDORA-2010-13249
链接:http://lists.fedoraproject.org/pipermail/package-announce/2010-August/045991.html
来源:NSFOCUS 名称:15631 链接:http://www.nsfocus.net/vulndb/15631
受影响实体
- Phpmyadmin Phpmyadmin:3.3.5.0<!--2000-1-1-->
- Phpmyadmin Phpmyadmin:2.11.0<!--2000-1-1-->
- Phpmyadmin Phpmyadmin:2.11.1.0<!--2000-1-1-->
- Phpmyadmin Phpmyadmin:2.11.1.2<!--2000-1-1-->
- Phpmyadmin Phpmyadmin:2.11.1.1<!--2000-1-1-->
补丁
- phpMyAdmin-3.3.7-all-languages<!---->
- phpMyAdmin-3.3.7-all-languages<!---->
- phpMyAdmin-3.3.7-all-languages<!---->
- phpMyAdmin-3.3.7-all-languages<!---->
还没有评论,来说两句吧...