Bug #74204 [Opn->Nab]: bruteforce phpmyadmin
| From: | requinix@php.net | Date: | Sat, 04 Mar 2017 11:38:56 +0000 |
| Subject: | Bug #74204 [Opn->Nab]: bruteforce phpmyadmin | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-207682@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74204&edit=1
ID: 74204
Updated by: requinix@php.net
Reported by: sreenathr10 at gmail dot com
Summary: bruteforce phpmyadmin
-Status: Open
+Status: Not a bug
Type: Bug
Package: *General Issues
Operating System: windows 10
PHP Version: 7.1.3RC1
Block user comment: N
Private report: N
New Comment:
We are not phpMyAdmin.
Previous Comments:
------------------------------------------------------------------------
[2017-03-04 11:28:19] sreenathr10 at gmail dot com
Description:
------------
Using brute force method i have accessed to phpmyadmin because there is no limitation in typing
username and password.
Test script:
---------------
Using bruteforce i got username and password so please add limitations in phpmyadmin
Expected result:
----------------
login successful
Actual result:
--------------
any body can login using bruteforce and upload shell into the server
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74204&edit=1