Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.801494
Kategorie:Web application abuses
Titel:phpMyAdmin 'phpinfo.php' Security bypass Vulnerability
Zusammenfassung:The host is running phpMyAdmin and is prone to security bypass; vulnerability.
Beschreibung:Summary:
The host is running phpMyAdmin and is prone to security bypass
vulnerability.

Vulnerability Insight:
The flaw is caused by missing authentication in the 'phpinfo.php' script
when 'PMA_MINIMUM_COMMON' is defined. This can be exploited to gain knowledge
of sensitive information by requesting the file directly.

Vulnerability Impact:
Successful exploitation will let the unauthenticated attackers to display
information related to PHP.

Affected Software/OS:
phpMyAdmin version prior to 3.4.0-beta1.

Solution:
Upgrade to phpMyAdmin version 3.4.0-beta1 or later

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2010-4481
Debian Security Information: DSA-2139 (Google Search)
http://www.debian.org/security/2010/dsa-2139
http://www.mandriva.com/security/advisories?name=MDVSA-2011:000
http://secunia.com/advisories/42485
http://secunia.com/advisories/42725
http://www.vupen.com/english/advisories/2010/3238
http://www.vupen.com/english/advisories/2011/0001
http://www.vupen.com/english/advisories/2011/0027
CopyrightCopyright (C) 2010 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.