Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.70509
Kategorie:Mandrake Local Security Checks
Titel:Mandriva Security Advisory MDVSA-2011:158 (phpmyadmin)
Zusammenfassung:NOSUMMARY
Beschreibung:Description:
The remote host is missing an update to phpmyadmin
announced via advisory MDVSA-2011:158.

Multiple vulnerabilities has been found and corrected in phpmyadmin:

Missing sanitization on the table, column and index names leads to
XSS vulnerabilities (CVE-2011-3181).

Firstly, if a row contains javascript code, after inline editing this
row and saving, the code is executed. Secondly, missing sanitization
on the db, table and column names leads to XSS vulnerabilities.

When the js_frame parameter of phpmyadmin.css.php is defined as an
array, an error message shows the full path of this file, leading to
possible further attacks (CVE-2011-3646).

Crafted values entered in the setup interface can produce XSS
also,
if the config directory exists and is writeable, the XSS payload can
be saved to this directory (CVE-2011-4064).

This upgrade provides the latest phpmyadmin version (3.4.6) to address
these vulnerabilities.

Affected: Enterprise Server 5.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDVSA-2011:158
http://www.phpmyadmin.net/home_page/security/PMASA-2011-13.php
http://www.phpmyadmin.net/home_page/security/PMASA-2011-14.php
http://www.phpmyadmin.net/home_page/security/PMASA-2011-15.php
http://www.phpmyadmin.net/home_page/security/PMASA-2011-16.php

Risk factor : High

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2011-3181
BugTraq ID: 49306
http://www.securityfocus.com/bid/49306
Debian Security Information: DSA-2391 (Google Search)
http://www.debian.org/security/2012/dsa-2391
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065854.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065824.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065829.html
http://www.mandriva.com/security/advisories?name=MDVSA-2011:158
http://secunia.com/advisories/45709
http://secunia.com/advisories/45990
Common Vulnerability Exposure (CVE) ID: CVE-2011-3646
http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069235.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069237.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069234.html
http://secunia.com/advisories/46874
Common Vulnerability Exposure (CVE) ID: CVE-2011-4064
BugTraq ID: 50175
http://www.securityfocus.com/bid/50175
http://securitytracker.com/id?1026199
CopyrightCopyright (c) 2012 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.