PHPMyAdmin Table参数跨站脚本攻击漏洞

漏洞信息详情

PHPMyAdmin Table参数跨站脚本攻击漏洞

漏洞简介

phpMyAdmin 2.8.2之前版本存在跨站脚本攻击(XSS)漏洞,远程攻击者可通过table参数注入任意Web脚本或HTML。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:

phpMyAdmin phpMyAdmin 2.0

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.0.1

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.0.2

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.0.3

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.0.4

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.0.5

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.1 .2

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.1

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.1 .1

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.2 pre1

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.2 rc3

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.2 pre2

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.2 rc2

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.2

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.2 rc1

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.2.2

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.2.3

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.2.4

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.2.5

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.2.6

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.3.1

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.3.2

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.4 .0

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.5 .0

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.5.1

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.5.2

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.5.3

phpMyAdmin phpMyAdmin-2.8.2.tar.gz

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.8.2.tar.gz? download

phpMyAdmin phpMyAdmin 2.5.4

phpMyAd

参考网址

来源: BID

名称: 18754

链接:http://www.securityfocus.com/bid/18754

来源: BUGTRAQ

名称: 20060630 phpMyAdmin : Cross-Site Scripting Vulnerability

链接:http://www.securityfocus.com/archive/1/archive/1/438870/100/0/threaded

来源: VUPEN

名称: ADV-2006-2622

链接:http://www.frsirt.com/english/advisories/2006/2622

来源: MISC

链接:http://securitynews.ir/advisories/phpmyadmin281.txt

来源: SECUNIA

名称: 20907

链接:http://secunia.com/advisories/20907

来源: www.phpmyadmin.net

链接:http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2006-4

来源: XF

名称: phpmyadmin-table-xss(27493)

链接:http://xforce.iss.net/xforce/xfdb/27493

来源: SREASON

名称: 1194

链接:http://securityreason.com/securityalert/1194

来源: SECUNIA

名称: 23086

链接:http://secunia.com/advisories/23086

来源: SUSE

名称: SUSE-SA:2006:071

链接:http://lists.suse.com/archive/suse-security-announce/2006-Nov/0010.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享