Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: php codes injection in phpMyAdmin version 2.5.7.

Re: php codes injection in phpMyAdmin version 2.5.7.

From: Marc Delisle <DelislMa_at_CollegeSherbrooke.qc.ca>
Date: 30 Jun 2004 19:43:11 -0000
('binary' encoding is not supported, stored as-is) In-Reply-To: <20040629025752.976.qmail_at_www.securityfocus.com>

The Internet, 2004-06-30

Greetings,

The phpMyAdmin development team announces
the availability of phpMyAdmin 2.5.7, patch level 1.
This version fixes the vulnerability dated 2004-06-29,
released on BUGTRAQ.
 
>From our Documentation.html, FAQ 8.2:
"We acknowledge that phpMyAdmin versions 2.5.1 to 2.5.7 are vulnerable to this problem,
 if each of the following conditions are met:

    * The Web server hosting phpMyAdmin is not running in safe mode.
    * In config.inc.php, $cfg['LeftFrameLight'] is set to FALSE (the default value of this parameter is TRUE).
    * There is no firewall blocking requests from the Web server to the attacking host."

We would like to put emphasis on the disappointment we feel when a bugreporter does not contact the authors of a software first, before posting any exploits. The common way to report this, is to give the developers a reasonable amount of time to respond to an exploit
before it is made public.

Marc Delisle, for the team.
Received on Jul 01 2004

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos