PHPMyAdmin 多个跨站脚本攻击(XSS)漏洞

漏洞信息详情

PHPMyAdmin 多个跨站脚本攻击(XSS)漏洞

漏洞简介

phpMyAdmin 2.6.0-pl2及更早版本中存在多个跨站脚本攻击(XSS)漏洞,远程攻击者可以通过(1) PmaAbsoluteUri参数、(2) read_dump.php中的zero_rows参数、(3) confirm表格或(4) 内部phpMyAdmin解析器生成的出错信息注入任意web脚本或HTML。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

phpMyAdmin phpMyAdmin 2.5 .0

phpMyAdmin phpMyAdmin 2.6.0-pl3

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.0-pl3.tar.gz?download

phpMyAdmin phpMyAdmin 2.5.1

phpMyAdmin phpMyAdmin 2.6.0-pl3

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.0-pl3.tar.gz?download

phpMyAdmin phpMyAdmin 2.5.2

phpMyAdmin phpMyAdmin 2.6.0-pl3

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.0-pl3.tar.gz?download

SuSE phpMyAdmin-2.5.3-34.noarch.rpm

ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/noarch/phpMyAdmin-2.

5.3-34.noarch.rpm

phpMyAdmin phpMyAdmin 2.5.4

phpMyAdmin phpMyAdmin 2.6.0-pl3

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.0-pl3.tar.gz?download

phpMyAdmin phpMyAdmin 2.5.5 -rc2

phpMyAdmin phpMyAdmin 2.6.0-pl3

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.0-pl3.tar.gz?download

phpMyAdmin phpMyAdmin 2.5.5

phpMyAdmin phpMyAdmin 2.6.0-pl3

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.0-pl3.tar.gz?download

phpMyAdmin phpMyAdmin 2.5.5 -rc1

phpMyAdmin phpMyAdmin 2.6.0-pl3

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.0-pl3.tar.gz?download

phpMyAdmin phpMyAdmin 2.5.5 pl1

phpMyAdmin phpMyAdmin 2.6.0-pl3

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.0-pl3.tar.gz?download

phpMyAdmin phpMyAdmin 2.5.6 -rc1

phpMyAdmin phpMyAdmin 2.6.0-pl3

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.0-pl3.tar.gz?download

SuSE phpMyAdmin-2.5.6-34.4.noarch.rpm

ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/noarch/phpMyAdmin-2.5.6-34.4.noarch.rpm

phpMyAdmin phpMyAdmin 2.5.7

phpMyAdmin phpMyAdmin 2.6.0-pl3

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.0-pl3.tar.gz?download

phpMyAdmin phpMyAdmin 2.5.7 pl1

phpMyAdmin phpMyAdmin 2.6.0-pl3

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.0-pl3.tar.gz?download

phpMyAdmin phpMyAdmin 2.6 .0pl1

phpMyAdmin phpMyAdmin 2.6.0-pl3

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.0-pl3.tar.gz?download

SuSE phpMyAdmin-2.6.0-4.4.noarch.rpm

ftp://ftp.suse.com/pub/suse/x86_64/update/9.2/rpm/noarch/phpMyAdmin-2.6.0-4.4.noarch.rpm

phpMyAdmin phpMyAdmin 2.6 .0pl2

phpMyAdmin phpMyAdmin 2.6.0-pl3

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.6.0-pl3.tar.gz?download

参考网址

来源: XF

名称: phpmyadmin-multiple-xss(18158)

链接:http://xforce.iss.net/xforce/xfdb/18158

来源: www.phpmyadmin.net

链接:http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2004-3

来源: MISC

链接:http://www.netvigilance.com/html/advisory0005.htm

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享