| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.61938 |
| Category: | Debian Local Security Checks |
| Title: | Debian Security Advisory DSA 1675-1 (phpmyadmin) |
| Summary: | Debian Security Advisory DSA 1675-1 (phpmyadmin) |
| Description: | The remote host is missing an update to phpmyadmin announced via advisory DSA 1675-1. Masako Oono discovered that phpMyAdmin, a web-based administration interface for MySQL, insufficiently sanitises input allowing a remote attacker to gather sensitive data through cross site scripting, provided that the user uses the Internet Explorer web browser. This update also fixes a regression introduced in DSA 1641, that broke changing of the language and encoding in the login screen. For the stable distribution (etch), these problems have been fixed in version 4:2.9.1.1-9. For the unstable distribution (sid), these problems have been fixed in version 4:2.11.8.1-3. We recommend that you upgrade your phpmyadmin package. Solution: http://www.securityspace.com/smysecure/catid.html?in=DSA%201675-1 |
| Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2008-4326 http://www.openwall.com/lists/oss-security/2008/09/22/2 Debian Security Information: DSA-1675 (Google Search) http://www.debian.org/security/2008/dsa-1675 SuSE Security Announcement: SUSE-SR:2009:003 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html http://jvn.jp/en/jp/JVN54824688/index.html http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000061.html http://osvdb.org/48511 http://secunia.com/advisories/31974 http://secunia.com/advisories/31992 http://www.vupen.com/english/advisories/2008/2657 http://secunia.com/advisories/32954 http://secunia.com/advisories/33822 |
| Copyright | Copyright (c) 2008 E-Soft Inc. http://www.securityspace.com |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|