漏洞信息详情
phpMyAdmin远程命令执行漏洞
- CNNVD编号:CNNVD-200412-482
- 危害等级: 高危
- CVE编号:
CVE-2004-2630
- 漏洞类型:
输入验证
- 发布时间:
2004-12-31
- 威胁类型:
远程
- 更新时间:
2005-12-21
- 厂 商:
phpmyadmin - 漏洞来源:
phpMyAdmin -
漏洞简介
phpMyAdmin 2.5.0至2.6.0-pl1版本的MIME转化系统(transformations/text_plain__external.inc.php)存在漏洞。远程攻击者借助未明向量中的shell元字符执行任意命令。
漏洞公告
Gentoo Linux has released advisory GLSA 200410-14 dealing with this issue. They have advised that all phpMyAdmin users should upgrade to the latest version:
# emerge sync
# emerge -pv “>=dev-db/phpmyadmin-2.6.0_p2”
# emerge “>=dev-db/phpmyadmin-2.6.0_p2”
Please see the referenced Gentoo advisory for more information.
The vendor has released phpMyAdmin 2.6.0 pl2 to address this issue.
phpMyAdmin phpMyAdmin 2.0
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
phpMyAdmin phpMyAdmin 2.0.1
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
phpMyAdmin phpMyAdmin 2.0.2
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
phpMyAdmin phpMyAdmin 2.0.3
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
phpMyAdmin phpMyAdmin 2.0.4
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
phpMyAdmin phpMyAdmin 2.0.5
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
phpMyAdmin phpMyAdmin 2.1 .2
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
phpMyAdmin phpMyAdmin 2.1
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
phpMyAdmin phpMyAdmin 2.1 .1
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
phpMyAdmin phpMyAdmin 2.2 pre1
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
phpMyAdmin phpMyAdmin 2.2 rc3
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
phpMyAdmin phpMyAdmin 2.2 pre2
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
phpMyAdmin phpMyAdmin 2.2 rc2
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
phpMyAdmin phpMyAdmin 2.2
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
phpMyAdmin phpMyAdmin 2.2 rc1
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
phpMyAdmin phpMyAdmin 2.2.2
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
phpMyAdmin phpMyAdmin 2.2.3
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
phpMyAdmin phpMyAdmin 2.2.4
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
phpMyAdmin phpMyAdmin 2.2.5
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
phpMyAdmin phpMyAdmin 2.2.6
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
phpMyAdmin phpMyAdmin 2.3.1
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
phpMyAdmin phpMyAdmin 2.3.2
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
phpMyAdmin phpMyAdmin 2.4 .0
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
phpMyAdmin phpMyAdmin 2.5 .0
-
phpMyAdmin phpMyAdmin 2.6.0-pl2
http://sourceforge.net/project/showfiles.php?group_id=23067&package_id
=16462&release_id=274709
参考网址
来源: XF
名称: phpmyadmin-command-execution(17698)
链接:http://xforce.iss.net/xforce/xfdb/17698
来源: BID
名称: 11391
链接:http://www.securityfocus.com/bid/11391
来源: www.phpmyadmin.net
链接:http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2004-2
来源: GENTOO
名称: GLSA-200410-14
链接:http://www.gentoo.org/security/en/glsa/glsa-200410-14.xml
来源: SECTRACK
名称: 1011761
链接:http://securitytracker.com/alerts/2004/Oct/1011761.html
来源: SECUNIA
名称: 12859
链接:http://secunia.com/advisories/12859
来源: SECUNIA
名称: 12813
链接:http://secunia.com/advisories/12813
来源: FULLDISC
名称: 20041018: phpMyAdmin: Vulnerability in MIME-based transformation
链接:http://marc.theaimsgroup.com/?l=full-disclosure&m=109810251501643&w=2
来源: BUGTRAQ
名称: 20041018 phpMyAdmin: Vulnerability in MIME-based transformation
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=109816584519779&w=2
来源: OSVDB
名称: 10715
链接:http://www.osvdb.org/10715