Bug 20402 - Multiple vulnerabilities: CVE-2009-1148, CVE-2009-1149, CVE-2009-1150, CVE-2009-1285
Summary: Multiple vulnerabilities: CVE-2009-1148, CVE-2009-1149, CVE-2009-1150, CVE-20...
Status: CLOSED FIXED
Alias: None
Product: Sisyphus
Classification: Development
Component: phpMyAdmin (show other bugs)
Version: unstable
Hardware: all Linux
: P3 blocker
Assignee: drool
QA Contact: qa-sisyphus
URL: http://www.phpmyadmin.net/home_page/s...
Keywords: security
Depends on: 22408
Blocks:
  Show dependency tree
 
Reported: 2009-06-10 10:37 MSD by Vladimir Lettiev
Modified: 2009-12-31 16:59 MSK (History)
2 users (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Vladimir Lettiev 2009-06-10 10:37:17 MSD
Обнаружено множество проблем безопасности в phpMyAdmin:

PMASA-2009-1 - The BLOB streaming feature allowed attacker to include arbitrary files and inject HTTP headers using crafted URL parameters.
PMASA-2009-2 - Cross-site scripting on export page using cookies.
PMASA-2009-3, PMASA-2009-4 - Insufficient output sanitizing when generating configuration file.

Исправление доступно в версиях >= 3.1.3.2 (на данный момент это 3.1.5).
Comment 1 Dmitriy Kulik 2009-12-25 11:18:18 MSK
Fixed