phpMyAdmin ‘$_REQUEST’ SQL注入漏洞

漏洞信息详情

phpMyAdmin ‘$_REQUEST’ SQL注入漏洞

漏洞简介

phpMyAdmin 2.11.5之前的版本访问$_REQUEST而获得一些非$_GET和$_POST的参数,这使得同一个域中的攻击者可以借助特制的cookies,无视某些变量,执行SQL注入和跨站请求伪造攻击。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

phpMyAdmin phpMyAdmin 2.10.0.1

phpMyAdmin phpMyAdmin-2.11.5-all-languages.tar.bz2

http://prdownloads.sourceforge.net/phpmyadmin/phpMyAdmin-2.11.5-all-languages.tar.bz2?download

参考网址

来源: BID

名称: 28068

链接:http://www.securityfocus.com/bid/28068

来源: www.phpmyadmin.net

链接:http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-1

来源: VUPEN

名称: ADV-2008-0758

; Patch Information

链接:http://www.frsirt.com/english/advisories/2008/0758

来源: VUPEN

名称: ADV-2008-0731

; Patch Information

链接:http://www.frsirt.com/english/advisories/2008/0731

来源: DEBIAN

名称: DSA-1557

链接:http://www.debian.org/security/2008/dsa-1557

来源: FEDORA

名称: FEDORA-2008-2229

链接:https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00100.html

来源: FEDORA

名称: FEDORA-2008-2189

链接:https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00069.html

来源: XF

名称: phpmyadmin-request-sql-injection(40968)

链接:http://xforce.iss.net/xforce/xfdb/40968

来源: MANDRIVA

名称: MDVSA-2008:131

链接:http://www.mandriva.com/security/advisories?name=MDVSA-2008:131

来源: GENTOO

名称: GLSA-200803-15

链接:http://www.gentoo.org/security/en/glsa/glsa-200803-15.xml

来源: SECUNIA

名称: 33822

链接:http://secunia.com/advisories/33822

来源: SECUNIA

名称: 32834

链接:http://secunia.com/advisories/32834

来源: SECUNIA

名称: 30816

链接:http://secunia.com/advisories/30816

来源: SECUNIA

名称: 29964

链接:http://secunia.com/advisories/29964

来源: SECUNIA

名称: 29287

链接:http://secunia.com/advisories/29287

来源: SECUNIA

名称: 29200

链接:http://secunia.com/advisories/29200

来源: SECUNIA

名称: 29143

链接:http://secunia.com/advisories/29143

来源: SUSE

名称: SUSE-SR:2009:003

链接:http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html

来源: SUSE

名称: SUSE-SR:2008:026

链接:http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享