Re: Re: PhpMyAdmin phpPgAdmin Security Issues

From: Date: Tue, 03 Jul 2001 16:40:26 +0000
Subject: Re: Re: PhpMyAdmin phpPgAdmin Security Issues
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-56009@lists.php.net to get a copy of this message
btw, that error looks more like a mysql setup / runtime problem. IE..is the server running? ----- Original Message ----- From: "Paul Burney" <burney@gseis.ucla.edu> To: "andreas (@work)" <myviva@utanet.at> Cc: "php mailing list 2" <php-general@lists.php.net> Sent: Tuesday, July 03, 2001 11:51 AM Subject: [PHP] Re: [PHP-DB] PhpMyAdmin phpPgAdmin Security Issues > on 7/3/01 5:47 AM, andreas (@work) (myviva@utanet.at) wrote: > > > ive got 3 servers (dedicated) with mysql 3.22.32 and above and phpMyAdmin > > 2.1.0 but i cant reproduce the vulnerability > > > i use advanced uthentication > > > http://ip/phpMyAdmin/sql.php?server=000cfgServers[000][host]=hello&btnDrop=N > > o&goto=/etc/passwd > > If that URL is copied correctly, it might be because there's no "&" between > the server=000 and the cfgServers[000][host]. > > If not, maybe your particular configuration isn't vulnerable. > > If you use a Apache Auth for access to the folder and normal auth in > phpmyadmin, you are not vulnerable to outsiders but *you* can still view a > server's sensitive files which can be really dangerous in a shared server > environment. > > Sincerely, > > Paul Burney > > +-------------------------+---------------------------------+ > | Paul Burney | P: 310.825.8365 | > | Webmaster && Programmer | E: <webmaster@gseis.ucla.edu> | > | UCLA -> GSE&IS -> ETU | W: > <http://www.gseis.ucla.edu/> | > +-------------------------+---------------------------------+ > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > >

« previous php.general (#56009) next »