Re: PhpMyAdmin phpPgAdmin Security Issues

From: Date: Tue, 03 Jul 2001 15:51:13 +0000
Subject: Re: PhpMyAdmin phpPgAdmin Security Issues
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-55996@lists.php.net to get a copy of this message
on 7/3/01 5:47 AM, andreas (@work) (myviva@utanet.at) wrote: > ive got 3 servers (dedicated) with mysql 3.22.32 and above and phpMyAdmin > 2.1.0 but i cant reproduce the vulnerability > i use advanced uthentication > WÖtÁ1Ãã}›ž > üXKUhttp://ip/phpMyAdmin/sql.php?server=000cfgServers[000][host]=hello&btnDrop=N > o&goto=/etc/passwd If that URL is copied correctly, it might be because there's no "&" between the server=000 and the cfgServers[000][host]. If not, maybe your particular configuration isn't vulnerable. If you use a Apache Auth for access to the folder and normal auth in phpmyadmin, you are not vulnerable to outsiders but *you* can still view a server's sensitive files which can be really dangerous in a shared server environment. Sincerely, Paul Burney +-------------------------+---------------------------------+ | Paul Burney | P: 310.825.8365 | | Webmaster && Programmer | E: <webmaster@gseis.ucla.edu> | | UCLA -> GSE&IS -> ETU | W: <http://www.gseis.ucla.edu/> | +-------------------------+---------------------------------+

« previous php.general (#55996) next »