Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.831480
Categoría:Mandrake Local Security Checks
Título:Mandriva Update for phpmyadmin MDVSA-2011:158 (phpmyadmin)
Resumen:The remote host is missing an update for the 'phpmyadmin'; package(s) announced via the referenced advisory.
Descripción:Summary:
The remote host is missing an update for the 'phpmyadmin'
package(s) announced via the referenced advisory.

Vulnerability Insight:
Multiple vulnerabilities has been found and corrected in phpmyadmin:

Missing sanitization on the table, column and index names leads to
XSS vulnerabilities (CVE-2011-3181).

Firstly, if a row contains javascript code, after inline editing this
row and saving, the code is executed. Secondly, missing sanitization
on the db, table and column names leads to XSS vulnerabilities.

When the js_frame parameter of phpmyadmin.css.php is defined as an
array, an error message shows the full path of this file, leading to
possible further attacks (CVE-2011-3646).

Crafted values entered in the setup interface can produce XSS. Also,
if the config directory exists and is writeable, the XSS payload can
be saved to this directory (CVE-2011-4064).

This upgrade provides the latest phpmyadmin version (3.4.6) to address
these vulnerabilities.

Affected Software/OS:
phpmyadmin on Mandriva Enterprise Server 5,
Mandriva Enterprise Server 5/X86_64

Solution:
Please Install the Updated Packages.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2011-3181
BugTraq ID: 49306
http://www.securityfocus.com/bid/49306
Debian Security Information: DSA-2391 (Google Search)
http://www.debian.org/security/2012/dsa-2391
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065854.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065824.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065829.html
http://www.mandriva.com/security/advisories?name=MDVSA-2011:158
http://secunia.com/advisories/45709
http://secunia.com/advisories/45990
Common Vulnerability Exposure (CVE) ID: CVE-2011-3646
http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069235.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069237.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069234.html
http://secunia.com/advisories/46874
Common Vulnerability Exposure (CVE) ID: CVE-2011-4064
BugTraq ID: 50175
http://www.securityfocus.com/bid/50175
http://securitytracker.com/id?1026199
CopyrightCopyright (C) 2011 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.