Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.67984
Kategorie:Debian Local Security Checks
Titel:Debian Security Advisory DSA 2097-1 (phpmyadmin)
Zusammenfassung:NOSUMMARY
Beschreibung:Description:
The remote host is missing an update to phpmyadmin
announced via advisory DSA 2097-1.

Several remote vulnerabilities have been discovered in phpMyAdmin, a tool
to administer MySQL over the web. The Common Vulnerabilities and Exposures
project identifies the following problems:

CVE-2010-3055

The configuration setup script does not properly sanitise its output
file, which allows remote attackers to execute arbitrary PHP code via
a crafted POST request. In Debian, the setup tool is protected through
Apache HTTP basic authentication by default.

CVE-2010-3056

Various cross site scripting issues have been discovered that allow
a remote attacker to inject arbitrary web script or HTML.

For the stable distribution (lenny), these problems have been fixed in
version 2.11.8.1-5+lenny5.

For the testing (squeeze) and unstable distribution (sid), these problems
have been fixed in version 3.3.5.1-1.

We recommend that you upgrade your phpmyadmin package.

Solution:
http://www.securityspace.com/smysecure/catid.html?in=DSA%202097-1

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2010-3055
BugTraq ID: 42591
http://www.securityfocus.com/bid/42591
Debian Security Information: DSA-2097 (Google Search)
http://www.debian.org/security/2010/dsa-2097
http://www.mandriva.com/security/advisories?name=MDVSA-2010:163
http://secunia.com/advisories/41058
http://secunia.com/advisories/41185
http://www.vupen.com/english/advisories/2010/2223
http://www.vupen.com/english/advisories/2010/2231
Common Vulnerability Exposure (CVE) ID: CVE-2010-3056
BugTraq ID: 42584
http://www.securityfocus.com/bid/42584
http://lists.fedoraproject.org/pipermail/package-announce/2010-August/045991.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-August/045997.html
http://www.mandriva.com/security/advisories?name=MDVSA-2010:164
http://yehg.net/lab/pr0js/advisories/phpmyadmin/%5Bphpmyadmin-3.3.5%5D_cross_site_scripting%28XSS%29
http://secunia.com/advisories/41000
CopyrightCopyright (c) 2010 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.