Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.68980
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-2139-1)
Summary:The remote host is missing an update for the Debian 'phpmyadmin' package(s) announced via the DSA-2139-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'phpmyadmin' package(s) announced via the DSA-2139-1 advisory.

Vulnerability Insight:
Several vulnerabilities have been discovered in phpMyAdmin, a tool to administer MySQL over the web. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2010-4329

Cross site scripting was possible in search, that allowed a remote attacker to inject arbitrary web script or HTML.

CVE-2010-4480

Cross site scripting was possible in errors, that allowed a remote attacker to inject arbitrary web script or HTML.

CVE-2010-4481

Display of PHP's phpinfo() function was available to world, but only if this functionality had been enabled (defaults to off). This may leak some information about the host system.

For the stable distribution (lenny), these problems have been fixed in version 2.11.8.1-5+lenny7.

For the testing (squeeze) and unstable distribution (sid), these problems have been fixed in version 3.3.7-3.

We recommend that you upgrade your phpmyadmin package.

Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: [link moved to references]

Affected Software/OS:
'phpmyadmin' package(s) on Debian 5.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2010-4329
BugTraq ID: 45100
http://www.securityfocus.com/bid/45100
Debian Security Information: DSA-2139 (Google Search)
http://www.debian.org/security/2010/dsa-2139
http://lists.fedoraproject.org/pipermail/package-announce/2010-December/051942.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-December/051956.html
http://www.mandriva.com/security/advisories?name=MDVSA-2010:244
http://www.osvdb.org/69516
http://secunia.com/advisories/42408
http://secunia.com/advisories/42477
http://secunia.com/advisories/42725
http://www.vupen.com/english/advisories/2010/3082
http://www.vupen.com/english/advisories/2010/3087
http://www.vupen.com/english/advisories/2010/3158
http://www.vupen.com/english/advisories/2011/0001
Common Vulnerability Exposure (CVE) ID: CVE-2010-4480
BugTraq ID: 45633
http://www.securityfocus.com/bid/45633
http://www.exploit-db.com/exploits/15699
http://www.mandriva.com/security/advisories?name=MDVSA-2011:000
http://secunia.com/advisories/42485
http://www.vupen.com/english/advisories/2010/3133
http://www.vupen.com/english/advisories/2011/0027
Common Vulnerability Exposure (CVE) ID: CVE-2010-4481
http://www.vupen.com/english/advisories/2010/3238
CopyrightCopyright (C) 2011 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.