phpMyAdmin远程命令执行漏洞

漏洞信息详情

phpMyAdmin远程命令执行漏洞

漏洞简介

phpMyAdmin 2.5.0至2.6.0-pl1版本的MIME转化系统(transformations/text_plain__external.inc.php)存在漏洞。远程攻击者借助未明向量中的shell元字符执行任意命令。

漏洞公告

Gentoo Linux has released advisory GLSA 200410-14 dealing with this issue. They have advised that all phpMyAdmin users should upgrade to the latest version:
# emerge sync
# emerge -pv “>=dev-db/phpmyadmin-2.6.0_p2”
# emerge “>=dev-db/phpmyadmin-2.6.0_p2”
Please see the referenced Gentoo advisory for more information.
The vendor has released phpMyAdmin 2.6.0 pl2 to address this issue.
phpMyAdmin phpMyAdmin 2.0

phpMyAdmin phpMyAdmin 2.0.1

phpMyAdmin phpMyAdmin 2.0.2

phpMyAdmin phpMyAdmin 2.0.3

phpMyAdmin phpMyAdmin 2.0.4

phpMyAdmin phpMyAdmin 2.0.5

phpMyAdmin phpMyAdmin 2.1 .2

phpMyAdmin phpMyAdmin 2.1

phpMyAdmin phpMyAdmin 2.1 .1

phpMyAdmin phpMyAdmin 2.2 pre1

phpMyAdmin phpMyAdmin 2.2 rc3

phpMyAdmin phpMyAdmin 2.2 pre2

phpMyAdmin phpMyAdmin 2.2 rc2

phpMyAdmin phpMyAdmin 2.2

phpMyAdmin phpMyAdmin 2.2 rc1

phpMyAdmin phpMyAdmin 2.2.2

phpMyAdmin phpMyAdmin 2.2.3

phpMyAdmin phpMyAdmin 2.2.4

phpMyAdmin phpMyAdmin 2.2.5

phpMyAdmin phpMyAdmin 2.2.6

phpMyAdmin phpMyAdmin 2.3.1

phpMyAdmin phpMyAdmin 2.3.2

phpMyAdmin phpMyAdmin 2.4 .0

phpMyAdmin phpMyAdmin 2.5 .0

参考网址

来源: XF
名称: phpmyadmin-command-execution(17698)
链接:http://xforce.iss.net/xforce/xfdb/17698

来源: BID
名称: 11391
链接:http://www.securityfocus.com/bid/11391

来源: www.phpmyadmin.net
链接:http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2004-2

来源: GENTOO
名称: GLSA-200410-14
链接:http://www.gentoo.org/security/en/glsa/glsa-200410-14.xml

来源: SECTRACK
名称: 1011761
链接:http://securitytracker.com/alerts/2004/Oct/1011761.html

来源: SECUNIA
名称: 12859
链接:http://secunia.com/advisories/12859

来源: SECUNIA
名称: 12813
链接:http://secunia.com/advisories/12813

来源: FULLDISC
名称: 20041018: phpMyAdmin: Vulnerability in MIME-based transformation
链接:http://marc.theaimsgroup.com/?l=full-disclosure&m=109810251501643&w=2

来源: BUGTRAQ
名称: 20041018 phpMyAdmin: Vulnerability in MIME-based transformation
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=109816584519779&w=2

来源: OSVDB
名称: 10715
链接:http://www.osvdb.org/10715

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享