Re: PhpMyAdmin phpPgAdmin Security Issues
| From: | Paul Burney | Date: | Tue, 03 Jul 2001 15:51:13 +0000 |
| Subject: | Re: PhpMyAdmin phpPgAdmin Security Issues | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-55996@lists.php.net to get a copy of this message | ||
on 7/3/01 5:47 AM, andreas (@work) (myviva@utanet.at) wrote:
> ive got 3 servers (dedicated) with mysql 3.22.32 and above and phpMyAdmin
> 2.1.0 but i cant reproduce the vulnerability
> i use advanced uthentication
> WÖtÁ1Ãã}›ž
> üXKUhttp://ip/phpMyAdmin/sql.php?server=000cfgServers[000][host]=hello&btnDrop=N
> o&goto=/etc/passwd
If that URL is copied correctly, it might be because there's no "&" between
the server=000 and the cfgServers[000][host].
If not, maybe your particular configuration isn't vulnerable.
If you use a Apache Auth for access to the folder and normal auth in
phpmyadmin, you are not vulnerable to outsiders but *you* can still view a
server's sensitive files which can be really dangerous in a shared server
environment.
Sincerely,
Paul Burney
+-------------------------+---------------------------------+
| Paul Burney | P: 310.825.8365 |
| Webmaster && Programmer | E: <webmaster@gseis.ucla.edu> |
| UCLA -> GSE&IS -> ETU | W: <http://www.gseis.ucla.edu/> |
+-------------------------+---------------------------------+