Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 198801 (CVE-2007-5976) - dev-db/phpmyadmin < 2.11.2.2 "db_create.php" persistent XSS and login XSS (CVE-2007-{5976,5977,6100})
Summary: dev-db/phpmyadmin < 2.11.2.2 "db_create.php" persistent XSS and login XSS (CV...
Status: RESOLVED FIXED
Alias: CVE-2007-5976
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/27630/
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-11-11 12:48 UTC by Ilya Eremin
Modified: 2008-03-06 09:49 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Ilya Eremin 2007-11-11 12:48:32 UTC
When creating a new database, a malicious user can use a client-side Web proxy to place malicious code in the "db" parameter of the POST request. Since db_create.php does not properly sanitize user-supplied input, an administrator could face a persistent XSS attack when the database names are displayed.

Sample Exploit Code:
db=>%22%27><img%20src%3d%22javascript:alert(%27XSS%27)%22>

2.11.2.1 is now out to fix this issue
From ChangeLog
- (2.11.2.1) fixed possible SQL injection using database name
- (2.11.2.1) fixed possible XSS in database name, 
  thanks to Omer Singer, The DigiTrust Group

Latest version in portage is 2.11.1.1, here's a full ChangeLog from that version
http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2007-11-11 13:40:36 UTC
Web-apps, please advise.
Comment 2 Ilya Eremin 2007-11-18 01:55:35 UTC
This is now CVE-2007-5977 and CVE-2007-5976
Comment 3 Ilya Eremin 2007-11-20 18:59:31 UTC
2.11.2.2 is now out fixing another XSS issue
http://www.nth-dimension.org.uk/pub/NDSA20071119.txt.asc
Comment 4 Robert Buchholz (RETIRED) gentoo-dev 2007-11-25 15:20:35 UTC
CVE-2007-6100 to the third issue.

Web-apps, please bump this package.
Comment 5 Gunnar Wrobel (RETIRED) gentoo-dev 2007-12-02 15:03:47 UTC
Added phpmyadmin-2.11.2.2 to the tree.

Targets: alpha amd64 hppa ppc ppc64 sparc x86
Comment 6 Markus Rothe (RETIRED) gentoo-dev 2007-12-02 18:50:03 UTC
ppc64 stable
Comment 7 Christian Faulhammer (RETIRED) gentoo-dev 2007-12-03 08:16:56 UTC
x86 stable
Comment 8 Steve Dibb (RETIRED) gentoo-dev 2007-12-04 02:26:09 UTC
amd64 stable
Comment 9 Jeroen Roovers (RETIRED) gentoo-dev 2007-12-04 17:20:22 UTC
Stable for HPPA.
Comment 10 Tobias Scherbaum (RETIRED) gentoo-dev 2007-12-04 19:23:19 UTC
ppc stable
Comment 11 Raúl Porcel (RETIRED) gentoo-dev 2007-12-05 12:36:31 UTC
alpha/sparc stable
Comment 12 Gunnar Wrobel (RETIRED) gentoo-dev 2007-12-05 12:47:12 UTC
removed insecure version from the tree. webapps done here.
Comment 13 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-12-10 22:04:44 UTC
time for vote here. I vote NO.
Comment 14 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2008-01-06 18:13:54 UTC
I tend to vote YES.
Comment 15 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2008-01-06 18:14:30 UTC
Bah, wrong bug.

Voting NO and closing.
Comment 16 Peter Volkov (RETIRED) gentoo-dev 2008-03-06 09:49:28 UTC
Does not affect current (2008.0) release. Removing release.