Welcome to the JaguarPC Community
JaguarPC
Sales: (888) 338-5261
Support: (888)-551-3050
Results 1 to 6 of 6

This is a discussion on PhpMyAdmin Advisory in the Open Discussion & Chit-chat forum
Just saw this in a SANS @RISK advisory email. Those of you running your own PhpMyAdmin installs may want to take note: (3) HIGH: phpMyAdmin ...

  1. #1
    Community Leader jason's Avatar
    Join Date
    Sep 2001
    Location
    Rochester, NY
    Posts
    6,003

    PhpMyAdmin Advisory

    Just saw this in a SANS @RISK advisory email. Those of you running your own PhpMyAdmin installs may want to take note:

    (3) HIGH: phpMyAdmin Remote Variable Overwrite
    Affected:
    phpMyAdmin version 2.7.0

    Description: phpMyAdmin, a PHP-based tool to manage MySQL databases,
    contains a remote variable overwrite vulnerability. An attacker can
    overwrite the value for "$import_blacklist" variable, which was
    originally devised to protect other variables from being overwritten.
    By overwriting this variable, an attacker can further overwrite other
    important variables such as "$GLOBALS". This can lead to PHP local and
    remote file include vulnerabilities that can be exploited to execute
    arbitrary PHP code.

    Status: phpMyAdmin confirmed, version 2.7.0p1 has been released.

    References:
    Posting by Stefan Essar
    http://archives.neohapsis.com/archiv...5-12/0069.html
    Importance of $GLOBALS Variable
    http://www.hardened-php.net/index.76.html
    phpMyAdmin Fixes
    http://www.phpmyadmin.net/home_page/...php?relnotes=0
    SecurityFocus BID
    http://www.securityfocus.com/bid/15761
    --Jason
    Jason Pitoniak
    Interbrite Communications
    www.interbrite.com www.kodiakskorner.com

  2. #2
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Thanks, jason!

    I've been working a lot, and haven't had a chance to update phpMyAdmin in two weeks. Consequently, I'm two updates behind...
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  3. #3
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Okay, all upgraded! This version is LOTS better than 2.7.0-rc1

    BTW, if you haven't done so already, give the 'Arctic Ocean' theme a try. It is, by far, the best looking and most functional phpMyAdmin theme ever!!!
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  4. #4
    Darth Admin (aka Jag) JPC-Greg's Avatar
    Join Date
    Sep 1998
    Posts
    5,201
    wheres this theme located, included?
    Greg L. | Chief Executive Officer
    JaguarPC.com

    Helpful Links
    Knowledge Base | Network Status

    Need a Manager?
    (pm) | (email) David, Customer Service Manager
    (pm) | (email) Zach, Community Liason, Sales manager
    (pm) | (email) Masood, Chief Technical Officer
    (pm) | (email) Les, Chief Operations Officer

  5. #5
    Darth Admin (aka Jag) JPC-Greg's Avatar
    Join Date
    Sep 1998
    Posts
    5,201
    found it
    Greg L. | Chief Executive Officer
    JaguarPC.com

    Helpful Links
    Knowledge Base | Network Status

    Need a Manager?
    (pm) | (email) David, Customer Service Manager
    (pm) | (email) Zach, Community Liason, Sales manager
    (pm) | (email) Masood, Chief Technical Officer
    (pm) | (email) Les, Chief Operations Officer

  6. #6
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Quote Originally Posted by Jag
    found it
    Sorry about that! They find their themes pretty well...

    http://www.phpmyadmin.net/home_page/...ads.php?themes
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •