| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.803077 |
| Category: | Web application abuses |
| Title: | WordPress Portable phpMyAdmin Plugin 'wp-pma-mod' Security Bypass Vulnerability |
| Summary: | Check if WP Portable phpMyAdmin Plugin is vulnerable to Security Bypass |
| Description: | Overview: This host is installed with WordPress Portable phpMyAdmin Plugin and is prone to security bypass vulnerability. Vulnerability Insight: The plugin fails to verify an existing WordPress session when accessing the plugin file path directly. An attacker can get a full phpMyAdmin console with the privilege level of the MySQL configuration of WordPress by accessing 'wp-content/plugins/portable-phpmyadmin/wp-pma-mod'. Impact: Successful exploitation will allow remote attackers to gain sensitive information. Impact Level: Application Affected Software/OS: WordPress Portable phpMyAdmin plugin version 1.3.0 Fix: Upgrade to the WordPress Portable phpMyAdmin Plugin 1.3.1 or later, For updates refer to http://wordpress.org/extend/plugins/portable-phpmyadmin/ References: http://osvdb.org/88391 http://secunia.com/advisories/51520/ http://xforce.iss.net/xforce/xfdb/80654 http://seclists.org/bugtraq/2012/Dec/91 http://www.exploit-db.com/exploits/23356/ http://packetstormsecurity.org/files/118805/WordPress-portable-phpMyAdmin-1.3.0-Authentication-Bypass.html |
| Cross-Ref: |
BugTraq ID: 56920 Common Vulnerability Exposure (CVE) ID: CVE-2012-5469 Bugtraq: 20121212 'portable-phpMyAdmin (WordPress Plugin)' Authentication Bypass (CVE-2012-5469) (Google Search) http://archives.neohapsis.com/archives/bugtraq/2012-12/0092.html http://wordpress.org/extend/plugins/portable-phpmyadmin/changelog/ |
| Copyright | Copyright (c) 2012 Greenbone Networks GmbH |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|