First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 198801
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Ilya Eremin <eremini@ntlworld.com>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 198801 depends on: Show dependency tree
Show dependency graph
Bug 198801 blocks:

Additional Comments: (this is where you put emerge --info)







View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-11-11 12:48 0000
When creating a new database, a malicious user can use a client-side Web proxy
to place malicious code in the "db" parameter of the POST request. Since
db_create.php does not properly sanitize user-supplied input, an administrator
could face a persistent XSS attack when the database names are displayed.

Sample Exploit Code:
db=>%22%27><img%20src%3d%22javascript:alert(%27XSS%27)%22>

2.11.2.1 is now out to fix this issue
From ChangeLog
- (2.11.2.1) fixed possible SQL injection using database name
- (2.11.2.1) fixed possible XSS in database name, 
  thanks to Omer Singer, The DigiTrust Group

Latest version in portage is 2.11.1.1, here's a full ChangeLog from that
version
http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0

------- Comment #1 From Robert Buchholz 2007-11-11 13:40:36 0000 -------
Web-apps, please advise.

------- Comment #2 From Ilya Eremin 2007-11-18 01:55:35 0000 -------
This is now CVE-2007-5977 and CVE-2007-5976

------- Comment #3 From Ilya Eremin 2007-11-20 18:59:31 0000 -------
2.11.2.2 is now out fixing another XSS issue
http://www.nth-dimension.org.uk/pub/NDSA20071119.txt.asc

------- Comment #4 From Robert Buchholz 2007-11-25 15:20:35 0000 -------
CVE-2007-6100 to the third issue.

Web-apps, please bump this package.

------- Comment #5 From Gunnar Wrobel 2007-12-02 15:03:47 0000 -------
Added phpmyadmin-2.11.2.2 to the tree.

Targets: alpha amd64 hppa ppc ppc64 sparc x86

------- Comment #6 From Markus Rothe 2007-12-02 18:50:03 0000 -------
ppc64 stable

------- Comment #7 From Christian Faulhammer 2007-12-03 08:16:56 0000 -------
x86 stable

------- Comment #8 From Steve Dibb 2007-12-04 02:26:09 0000 -------
amd64 stable

------- Comment #9 From Jeroen Roovers 2007-12-04 17:20:22 0000 -------
Stable for HPPA.

------- Comment #10 From Tobias Scherbaum 2007-12-04 19:23:19 0000 -------
ppc stable

------- Comment #11 From Raúl Porcel 2007-12-05 12:36:31 0000 -------
alpha/sparc stable

------- Comment #12 From Gunnar Wrobel 2007-12-05 12:47:12 0000 -------
removed insecure version from the tree. webapps done here.

------- Comment #13 From Pierre-Yves Rofes 2007-12-10 22:04:44 0000 -------
time for vote here. I vote NO.

------- Comment #14 From Sune Kloppenborg Jeppesen 2008-01-06 18:13:54 0000 -------
I tend to vote YES.

------- Comment #15 From Sune Kloppenborg Jeppesen 2008-01-06 18:14:30 0000 -------
Bah, wrong bug.

Voting NO and closing.

------- Comment #16 From Peter Volkov 2008-03-06 09:49:28 0000 -------
Does not affect current (2008.0) release. Removing release.

First Last Prev Next    No search results available      Search page      Enter new bug