|
|
| |
|
| |
phpMyAdmin: local file inclusion and XSS
| Package(s): | phpmyadmin |
CVE #(s): | CVE-2005-2869
CVE-2005-3300
CVE-2005-3301
|
| Created: | October 25, 2005 |
Updated: | November 18, 2005 |
| Description: |
Stefan Esser discovered that by calling certain PHP files directly, it
was possible to workaround the grab_globals.lib.php security model and
overwrite the $cfg configuration array. Systems running PHP in safe
mode are not affected. Futhermore, Tobias Klein reported several
cross-site-scripting issues resulting from insufficient user input
sanitizing. A local attacker may exploit this vulnerability by sending
malicious requests, causing the execution of arbitrary code with the rights
of the user running the web server. Furthermore, the cross-site scripting
issues give a remote attacker the ability to inject and execute malicious
script code or to steal cookie-based authentication credentials,
potentially compromising the victim's browser. |
| Alerts: |
|
( Log in to post comments)
|
|
|