AplusWebMaster
Topic Starter
FYI…
- http://isc.sans.org/diary.php?storyid=921
Last Updated: 2005-12-08 22:35:23 UTC
"…Stefan Esser published a critical vulnerability in phpMyAdmin, popular web based MySQL administration package. What's interesting about this vulnerability is that, in fact, it happens in the code which should protect the application.
The variable $import_blacklist is supposed to list variables that may not be overwritten. However, as this variable is not protected, an attacker can overwrite it and change the blacklist, after which this can be exploited to execute arbitrary script code in user's browser session, in the context of the site running a vulnerable installation of phpMyAdmin.
If you use this product, be sure to upgrade to phpMyAdmin 2.7.0-p1 from - http://sourceforge.net/project/showfiles.php?group_id=23067.
The original advisory is at
- http://www.hardened-php.net/advisory_252005.110.html …"
"Risk: Critical…
Recommendation:
It is strongly recommended to upgrade to the new version of phpMyAdmin which you can download at:
- http://www.phpmyadmin.net/home_page/downloads.php …"
Also:
- http://secunia.com/advisories/17925/

- http://isc.sans.org/diary.php?storyid=921
Last Updated: 2005-12-08 22:35:23 UTC
"…Stefan Esser published a critical vulnerability in phpMyAdmin, popular web based MySQL administration package. What's interesting about this vulnerability is that, in fact, it happens in the code which should protect the application.
The variable $import_blacklist is supposed to list variables that may not be overwritten. However, as this variable is not protected, an attacker can overwrite it and change the blacklist, after which this can be exploited to execute arbitrary script code in user's browser session, in the context of the site running a vulnerable installation of phpMyAdmin.
If you use this product, be sure to upgrade to phpMyAdmin 2.7.0-p1 from - http://sourceforge.net/project/showfiles.php?group_id=23067.
The original advisory is at
- http://www.hardened-php.net/advisory_252005.110.html …"
"Risk: Critical…
Recommendation:
It is strongly recommended to upgrade to the new version of phpMyAdmin which you can download at:
- http://www.phpmyadmin.net/home_page/downloads.php …"
Also:
- http://secunia.com/advisories/17925/