LWN.net Logo

phpmyadmin: php code execution

Package(s):phpmyadmin CVE #(s):CVE-2010-3055
Created:August 30, 2010 Updated:September 13, 2010
Description: From the Debian advisory:

The configuration setup script does not properly sanitise its output file, which allows remote attackers to execute arbitrary PHP code via a crafted POST request. In Debian, the setup tool is protected through Apache HTTP basic authentication by default.

Alerts:
Debian DSA-2097-2 2010-09-11
Mandriva MDVSA-2010:163 2010-08-30
Debian DSA-2097-1 2010-08-29
Gentoo 201201-01 2012-01-04

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds