Executive Summary
Summary | |
---|---|
Title | phpmyadmin security update |
Informations | |||
---|---|---|---|
Name | DSA-2391 | First vendor Publication | 2012-01-22 |
Vendor | Debian | Last vendor Modification | 2012-01-22 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 4.3 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Several vulnerabilities have been discovered in phpMyAdmin, a tool to administer MySQL over the web. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2011-4107 The XML import plugin allowed a remote attacker to read arbitrary files via XML data containing external entity references. CVE-2011-1940, CVE-2011-3181 Cross site scripting was possible in the table tracking feature, allowing a remote attacker to inject arbitrary web script or HTML. The oldstable distribution (lenny) is not affected by these problems. For the stable distribution (squeeze), these problems have been fixed in version 4:3.3.7-7. For the testing distribution (wheezy) and unstable distribution (sid), these problems have been fixed in version 4:3.4.7.1-1. We recommend that you upgrade your phpmyadmin packages. |
Original Source
Url : http://www.debian.org/security/2012/dsa-2391 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
67 % | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') (CWE/SANS Top 25) |
33 % | CWE-611 | Information Leak Through XML External Entity File Disclosure |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:15400 | |||
Oval ID: | oval:org.mitre.oval:def:15400 | ||
Title: | DSA-2391-1 phpmyadmin -- several | ||
Description: | Several vulnerabilities have been discovered in phpMyAdmin, a tool to administer MySQL over the web. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2011-4107 The XML import plugin allowed a remote attacker to read arbitrary files via XML data containing external entity references. CVE-2011-1940, CVE-2011-3181 Cross site scripting was possible in the table tracking feature, allowing a remote attacker to inject arbitrary web script or HTML. The oldstable distribution is not affected by these problems. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2391-1 CVE-2011-1940 CVE-2011-3181 CVE-2011-4107 | Version: | 7 |
Platform(s): | Debian GNU/Linux 6.0 Debian GNU/kFreeBSD 6.0 | Product(s): | phpmyadmin |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
ExploitDB Exploits
id | Description |
---|---|
2012-01-14 | phpMyAdmin 3.3.X and 3.4.X - Local File Inclusion via XXE Injection |
OpenVAS Exploits
Date | Description |
---|---|
2012-04-02 | Name : Fedora Update for phpMyAdmin FEDORA-2011-11477 File : nvt/gb_fedora_2011_11477_phpMyAdmin_fc16.nasl |
2012-03-19 | Name : Fedora Update for phpMyAdmin FEDORA-2011-15841 File : nvt/gb_fedora_2011_15841_phpMyAdmin_fc16.nasl |
2012-02-12 | Name : Gentoo Security Advisory GLSA 201201-01 (phpMyAdmin) File : nvt/glsa_201201_01.nasl |
2012-02-11 | Name : Debian Security Advisory DSA 2391-1 (phpmyadmin) File : nvt/deb_2391_1.nasl |
2012-01-09 | Name : Mandriva Update for phpmyadmin MDVSA-2011:198 (phpmyadmin) File : nvt/gb_mandriva_MDVSA_2011_198.nasl |
2011-11-25 | Name : Fedora Update for phpMyAdmin FEDORA-2011-15831 File : nvt/gb_fedora_2011_15831_phpMyAdmin_fc14.nasl |
2011-11-25 | Name : Fedora Update for phpMyAdmin FEDORA-2011-15846 File : nvt/gb_fedora_2011_15846_phpMyAdmin_fc15.nasl |
2011-10-31 | Name : Mandriva Update for phpmyadmin MDVSA-2011:158 (phpmyadmin) File : nvt/gb_mandriva_MDVSA_2011_158.nasl |
2011-09-21 | Name : FreeBSD Ports: phpMyAdmin File : nvt/freebsd_phpMyAdmin26.nasl |
2011-09-16 | Name : Fedora Update for phpMyAdmin FEDORA-2011-11594 File : nvt/gb_fedora_2011_11594_phpMyAdmin_fc14.nasl |
2011-09-16 | Name : Fedora Update for phpMyAdmin FEDORA-2011-11630 File : nvt/gb_fedora_2011_11630_phpMyAdmin_fc15.nasl |
2011-08-30 | Name : phpMyAdmin Tracking Feature Multiple Cross Site Scripting Vulnerabilities File : nvt/gb_phpmyadmin_49306.nasl |
0000-00-00 | Name : FreeBSD Ports: phpMyAdmin File : nvt/freebsd_phpMyAdmin29.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
76798 | phpMyadmin libraries/import/xml.php XML Data Entity References Parsing Remote... |
74781 | phpMyAdmin Tracking Feature Multiple Field XSS phpMyAdmin contains a flaw in the tracking feature that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via the 'table', 'column' and 'index' names before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server. |
72843 | phpMyAdmin Database Table Name Tracking Page XSS phpMyAdmin contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed when creating database table names before use in the Tracking page. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2011-14.nasl - Type : ACT_GATHER_INFO |
2012-05-21 | Name : The remote web server hosts a PHP application that is affected by an informat... File : phpmyadmin_pmasa_2011_17.nasl - Type : ACT_GATHER_INFO |
2012-01-23 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2391.nasl - Type : ACT_GATHER_INFO |
2012-01-05 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201201-01.nasl - Type : ACT_GATHER_INFO |
2011-11-23 | Name : The remote Fedora host is missing a security update. File : fedora_2011-15831.nasl - Type : ACT_GATHER_INFO |
2011-11-23 | Name : The remote Fedora host is missing a security update. File : fedora_2011-15841.nasl - Type : ACT_GATHER_INFO |
2011-11-23 | Name : The remote Fedora host is missing a security update. File : fedora_2011-15846.nasl - Type : ACT_GATHER_INFO |
2011-11-14 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_1f6ee7080d2211e1b5bd14dae938ec40.nasl - Type : ACT_GATHER_INFO |
2011-09-14 | Name : The remote Fedora host is missing a security update. File : fedora_2011-11477.nasl - Type : ACT_GATHER_INFO |
2011-09-14 | Name : The remote Fedora host is missing a security update. File : fedora_2011-11594.nasl - Type : ACT_GATHER_INFO |
2011-09-14 | Name : The remote Fedora host is missing a security update. File : fedora_2011-11630.nasl - Type : ACT_GATHER_INFO |
2011-08-29 | Name : The remote web server contains a PHP application that is affected by multiple... File : phpmyadmin_pmasa_2011_13.nasl - Type : ACT_GATHER_INFO |
2011-08-25 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_75e26236ce9e11e0b26a00215c6a37bb.nasl - Type : ACT_GATHER_INFO |
2011-06-09 | Name : The remote web server contains a PHP application that is affected by multiple... File : phpmyadmin_pmasa_2011_3.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2016-04-26 21:49:59 |
|
2014-02-17 11:30:45 |
|
2013-05-11 00:44:16 |
|