|| Hotline : 800 2378 ||  To contact CERT-MU send e-mail on --> info[at]cert-mu.gov.mu ||  To report incident e-mail on --> incident[at]cert-mu.gov.mu || To report Vulnerabilities send e-mail on --> Vulnerability[at]cert-mu.gov.mu ||
    Constituency
    Authority
    Vol. 2, Feb 2012
    Vol. 1, Oct 2011
    World CERTs
    Email Abuse
 
 
Authorized to use CERT(TM) - CERT is a mark owned by Carnegie Mellon University
 
 
 
 
 
 
 
 
 
 
 
 


   
 

CERT-MU AD-2010-3

Multiple Vulnerabilities in phpMyAdmin

Original issue date: 8 February, 2010

Overview

Multiple vulnerabilities have been reported in phpMyAdmin versions prior to 2.11.10, which could allow a remote attacker to bypass certain security restrictions and conduct cross-site request forgery attacks.

Description

  • Temporary Directory Permission Vulnerability

    This vulnerability is caused due to libraries /File.class.php in phpMyAdmin creates a temporary directory with 0777 permissions and uses predictable filenames for temporary files, which could be exploited to modify files.

  • Temporary File Predictible Filename Vulnerability

    This vulnerability is caused due to libraries /File.class.php in phpMyAdmin uses predictable filenames for temporary files, which could be exploited to manipulate certain files.

  • Multiple Parameter CSRF Vulnerability

    This vulnerability is caused due to the "/scripts/setup.php" script using the "unserialize()" function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks.
Software Affected

  • phpMyAdmin versions prior to 2.11.10

Impact

Severity Rating: High

Solution

Upgrade to phpMyAdmin 3.0.0 or 2.11.10.
http://www.phpmyadmin.net/home_page/downloads.php

Disclaimer

The information provided herein is on "as is" basis, without warranty of any kind.

Vendor Information

phpMyAdmin
http://www.phpmyadmin.net/home_page/downloads.php

CVE Name

CVE-2008-7251
CVE-2008-7252
CVE-2009-4605

References

phpMyAdmin

http://www.phpmyadmin.net/home_page/security/PMASA-2010-1.php
http://www.phpmyadmin.net/home_page/security/PMASA-2010-2.php
http://www.phpmyadmin.net/home_page/security/PMASA-2010-3.php

SecurityFocus

http://www.securityfocus.com/bid/37826/

Secunia

http://secunia.com/advisories/38211/

XFocus

http://xforce.iss.net/xforce/xfdb/55671

VUPEN Security

http://www.vupen.com/english/advisories/2010/0151

SecurityLab

http://en.securitylab.ru/nvd/389930.php

 
 
News & Events
Safer Internet Day 2012
Computer Security Day 2011
Workshop on Cloud Security
Workshop on Mobile Security
Certificate Award Ceremony for Trainings in Information Security Management

  more...
 
Virus Alerts
RSS Feed
 
 
 

Last Updated 20-Jul-2011
Disclaimer Maintained & Hosted by NCB
This site is best viewed in 1024 x 768 resolution. Internet Explorer 6.0 +

09-Jul-2011