PT-2007-1223 · Phpmyadmin · Phpmyadmin
Benjamin Mossé
+1
·
Published
2007-01-19
·
Updated
2016-11-18
·
CVE-2006-6943
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
PhpMyAdmin versions prior to 2.9.1.1
Description:
The issue allows remote attackers to obtain the full server path. This can be achieved through direct requests to certain scripts, such as scripts/check lang.php and themes/darkblue orange/layout.inc.php. Additionally, the issue can be exploited via specific array arguments to index.php, including
lang[], target[], db[], goto[], table[], and tbl group[]. Other vulnerable parameters include the back[] argument to sql.php, an invalid sort by parameter to server databases.php, and the db parameter to db printview.php.Recommendations:
For versions prior to 2.9.1.1, update to version 2.9.1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable scripts and parameters, such as scripts/check lang.php, themes/darkblue orange/layout.inc.php, and the specified array arguments to index.php, until a patch is applied. Avoid using the vulnerable parameters, including
lang[], target[], db[], goto[], table[], tbl group[], back[], sort by, and db, in the affected API endpoints until the issue is resolved.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpmyadmin