LWN.net Logo

phpMyAdmin: insufficient output sanitizing

Package(s):phpMyAdmin CVE #(s):CVE-2009-1285
Created:April 16, 2009 Updated:April 22, 2009
Description: phpMyAdmin has a vulnerability involving insufficient output sanitizing. The phpMyAdmin security report states:

Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file. Combined with ability to save files on server, this can allow unauthenticated users to execute arbitrary PHP code. This issue is on different parameters than PMASA-2009-3 and it was missed out of our radar because it was not existing in 2.11.x branch.

Alerts:
Fedora FEDORA-2009-3700 2009-04-15
Fedora FEDORA-2009-3692 2009-04-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds