AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
December 02, 2008, 07:40:29 AM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 4755 Members
Latest Member: typetroyk
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  Virtuozzo & Dedicated Servers  |  Security Alerts  |  Topic: phpMyAdmin "cookie.auth.lib.php" and "error.php" Cross Site Scripting 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: phpMyAdmin "cookie.auth.lib.php" and "error.php" Cross Site Scripting  (Read 1064 times)
TJ
Tech Team
Hero Member
********
Offline Offline

Posts: 136



View Profile
phpMyAdmin "cookie.auth.lib.php" and "error.php" Cross Site Scripting
« on: August 31, 2005, 12:00:56 AM »

* Technical Description *

Two vulnerabilities were identified in phpMyAdmin, which may be exploited by malicious users to conduct cross site scripting attacks.

The first flaw is due to an input validation error in the "error.php" script that does not properly filter a specially crafted "error" parameter, which may be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser.

The second issue is due to an input validation error in the "libraries/auth/cookie.auth.lib.php" script that does not properly filter specially crafted parameters, which may be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser.

 * Affected Products *

phpMyAdmin versions prior to 2.6.4-rc1

 * Solution *

Upgrade to phpMyAdmin version 2.6.4-rc1 :
http://www.phpmyadmin.net/home_page/downloads.php

 * References *

http://www.frsirt.com/english/advisories/2005/1556
http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0
http://sourceforge.net/tracker/index.php?func=detail&aid=1265740&group_id=23067&atid=377408
http://sourceforge.net/tracker/index.php?func=detail&aid=1240880&group_id=23067&atid=377408
Logged
Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  Virtuozzo & Dedicated Servers  |  Security Alerts  |  Topic: phpMyAdmin "cookie.auth.lib.php" and "error.php" Cross Site Scripting « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!