PT-2018-6789 · Php+3 · Phpmyadmin+3

Isaac Bennetch

·

Publicado

2014-05-05

·

Atualizado

2022-05-13

·

CVE-2017-18264

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: phpMyAdmin versions 4.0 through 4.0.10.19 phpMyAdmin version 4.4.x phpMyAdmin version 4.6.x phpMyAdmin version 4.7.0 prereleases
Description: An issue allows the bypassing of restrictions caused by $cfg['Servers'][$i]['AllowNoPassword'] = false under certain PHP versions, such as version 5. This can allow users with no password set to log in, even if the administrator has set $cfg['Servers'][$i]['AllowNoPassword'] to false. The issue occurs due to some implementations of the PHP substr function returning false when given an empty string as the first argument.
Recommendations: For phpMyAdmin versions 4.0 through 4.0.10.19, update to version 4.0.10.20 or later. For phpMyAdmin version 4.4.x, update to a version outside of the 4.4.x range. For phpMyAdmin version 4.6.x, update to a version outside of the 4.6.x range. For phpMyAdmin version 4.7.0 prereleases, update to a release version of 4.7.0 or later.

Exploit

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1591
ALT-PU-2017-1604
CVE-2017-18264
DLA-1415-1
GHSA-5868-G58J-VRJ5
USN-4843-1

Produtos afetados

Alt Linux
Linuxmint
Ubuntu
Phpmyadmin