Executive Summary

Summary
TitleNew phpmyadmin packages fix several vulnerabilities
Informations
NameDSA-2097First vendor Publication2010-08-29
VendorDebianLast vendor Modification2010-09-11
Severity (Vendor) N/ARevision2

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Cvss Base Score7.5Attack RangeNetwork
Cvss Impact Score6.4Attack ComplexityLow
Cvss Expoit Score10AuthenticationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

The update in DSA 2097 for phpMyAdmin did not correctly apply the intended changes, thereby not completely addressing the vulnerabilities. Updated packages now fix the issues described in the original advisory text below.

Several remote vulnerabilities have been discovered in phpMyAdmin, a tool to administer MySQL over the web. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2010-3055

The configuration setup script does not properly sanitise its output file, which allows remote attackers to execute arbitrary PHP code via a crafted POST request. In Debian, the setup tool is protected through Apache HTTP basic authentication by default.

CVE-2010-3056

Various cross site scripting issues have been discovered that allow a remote attacker to inject arbitrary web script or HTML.

For the stable distribution (lenny), these problems have been fixed in version 2.11.8.1-5+lenny6.

For the testing (squeeze) and unstable distribution (sid), these problems have been fixed in version 3.3.5.1-1.

We recommend that you upgrade your phpmyadmin package.

Original Source

Url : http://www.debian.org/security/2010/dsa-2097

CWE : Common Weakness Enumeration

idName
CWE-264Permissions, Privileges, and Access Controls
CWE-79Failure to Preserve Web Page Structure ('Cross-site Scripting')

CPE : Common Platform Enumeration

TypeDescriptionCount
Application58

OpenVAS Exploits

DateDescription
2012-02-12Name : Gentoo Security Advisory GLSA 201201-01 (phpMyAdmin)
File : nvt/glsa_201201_01.nasl
2010-12-02Name : Fedora Update for phpMyAdmin FEDORA-2010-13402
File : nvt/gb_fedora_2010_13402_phpMyAdmin_fc14.nasl
2010-10-10Name : Debian Security Advisory DSA 2097-1 (phpmyadmin)
File : nvt/deb_2097_1.nasl
2010-10-10Name : Debian Security Advisory DSA 2097-2 (phpmyadmin)
File : nvt/deb_2097_2.nasl
2010-10-10Name : FreeBSD Ports: phpMyAdmin
File : nvt/freebsd_phpMyAdmin21.nasl
2010-09-07Name : Mandriva Update for phpmyadmin MDVSA-2010:164 (phpmyadmin)
File : nvt/gb_mandriva_MDVSA_2010_164.nasl
2010-08-30Name : phpMyAdmin Multiple Cross Site Scripting Vulnerabilities
File : nvt/gb_phpmyadmin_42584.nasl
2010-08-30Name : phpMyAdmin Configuration File PHP Code Injection Vulnerability
File : nvt/gb_phpmyadmin_42591.nasl
2010-08-24Name : Fedora Update for phpMyAdmin FEDORA-2010-13249
File : nvt/gb_fedora_2010_13249_phpMyAdmin_fc13.nasl
2010-08-24Name : Fedora Update for phpMyAdmin FEDORA-2010-13258
File : nvt/gb_fedora_2010_13258_phpMyAdmin_fc12.nasl

Open Source Vulnerability Database (OSVDB)

idDescription
67491phpMyAdmin libraries/sqlparser.lib.php Unspecified Parameter XSS
67490phpMyAdmin libraries/sanitizing.lib.php Unspecified Parameter XSS
67489phpMyAdmin libraries/db_info.inc.php Unspecified Parameter XSS
67488phpMyAdmin libraries/dbi/mysqli.dbi.lib.php Unspecified Parameter XSS
67487phpMyAdmin libraries/dbi/mysql.dbi.lib.php Unspecified Parameter XSS
67486phpMyAdmin libraries/database_interface.lib.php Unspecified Parameter XSS
67485phpMyAdmin libraries/common.lib.php Unspecified Parameter XSS
67343phpMyAdmin Extension for TYPO3 Multiple Unspecified XSS
67325phpMyAdmin tbl_sql.php Unspecified Parameter XSS
67324phpMyAdmin tbl_replace.php fields[multi_edit][] Parameter XSS
67323phpMyAdmin sql.php Multiple Parameter XSS
67322phpMyAdmin setup/config.php DefaultLang Parameter XSS
67321phpMyAdmin server_privileges.php Multiple Parameter XSS
67320phpMyAdmin server_databases.php sort_by Parameter XSS
67319phpMyAdmin js/messages.php db Parameter XSS
67318phpMyAdmin db_structure.php sort Parameter XSS
67317phpMyAdmin db_sql.php delimiter Parameter XSS
67316phpMyAdmin db_search.php field_str Parameter XSS
67310phpMyAdmin setup.php Configuration File Arbitrary PHP Code Injection

Nessus® Vulnerability Scanner

DateDescription
2012-01-05Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201201-01.nasl - Type : ACT_GATHER_INFO
2010-08-30Name : The remote Debian host is missing a security-related update.
File : debian_DSA-2097.nasl - Type : ACT_GATHER_INFO
2010-08-27Name : The remote web server contains a PHP application that may allow execution of ...
File : phpmyadmin_pmasa_2010_4.nasl - Type : ACT_ATTACK
2010-08-24Name : The remote Fedora host is missing a security update.
File : fedora_2010-13402.nasl - Type : ACT_GATHER_INFO
2010-08-23Name : The remote Fedora host is missing a security update.
File : fedora_2010-13249.nasl - Type : ACT_GATHER_INFO
2010-08-23Name : The remote Fedora host is missing a security update.
File : fedora_2010-13258.nasl - Type : ACT_GATHER_INFO
2010-08-23Name : The remote FreeBSD host is missing one or more security-related updates.
File : freebsd_pkg_274922b8ad2011dfaf1f00e0814cab4e.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
DateInformations
2014-02-17 11:29:37
  • Multiple Updates