Bug 11899 - phpMyAdmin XSRF vulnerabilities
: phpMyAdmin XSRF vulnerabilities
Status: CLOSED FIXED
Product: Security
Classification: Unclassified
Component: Spell Issues
: unspecified
: Other other
: P2 normal
Assigned To: Security
http://www.phpmyadmin.net/home_page/s...
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2006-05-21 17:34 UTC by Ladislav Hagara (lace)
Modified: 2006-06-11 11:02 UTC (History)
1 user (show)

See Also:
hgr: fixed_in_lesser_branch+
v.merkatz: integrate_to_stable_grimoire+
v.merkatz: integrate_to_stable‑rc_grimoire+
hgr: SECURITY_PATCH_incremented+
hgr: sm‑security_note_sent+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Ladislav Hagara (lace) 2006-05-21 17:34:01 UTC
phpMyAdmin security announcement PMASA-2006-3

Announcement-ID: PMASA-2006-3
Date: 2006-05-20

Summary:
XSRF vulnerabilities

Description:
It was possible to inject arbitrary SQL commands by forcing an authenticated
user to follow a crafted link.

Severity:
Such issue is quite common in many PHP applications and users should take care
what links they follow. We consider these vulnerabilities to be quite dangerous.

Affected versions:
Some versions previous to 2.8.1 suffer from this vulneribility.
Solution:
Upgrade to phpMyAdmin 2.8.1.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1804

For further information and in case of questions, please contact the phpMyAdmin
team. Our website is http://www.phpmyadmin.net/.

---
Fixed in devel and test grimoire.
Comment 1 Ladislav Hagara (lace) 2006-05-21 17:36:21 UTC
p4 changes 79634 and 79635 
Comment 2 Ladislav Hagara (lace) 2006-05-22 04:30:54 UTC
integrated to stable-rc and stable
p4 describe 79643
Comment 3 Ladislav Hagara (lace) 2006-05-22 08:44:38 UTC
sm-security note [SMGLSA-2006-27]
http://lists.ibiblio.org/pipermail/sm-security/2006-May/000493.html