Bug 198801 - dev-db/phpmyadmin < 2.11.2.2 "db_create.php" persistent XSS and login XSS (CVE-2007-{5976,5977,6100})
|
Bug#:
198801
(CVE-2007-5976)
|
Product: Gentoo Security
|
Version: unspecified
|
Platform: All
|
|
OS/Version: Linux
|
Status: RESOLVED
|
Severity: minor
|
Priority: P2
|
|
Resolution: FIXED
|
Assigned To: security@gentoo.org
|
Reported By: eremini@ntlworld.com
|
|
Component: Vulnerabilities
|
|
|
URL:
http://secunia.com/advisories/27630/
|
|
Summary: dev-db/phpmyadmin < 2.11.2.2 "db_create.php" persistent XSS and login XSS (CVE-2007-{5976,5977,6100})
|
|
Keywords:
|
|
Status Whiteboard: B4 [noglsa]
|
|
Opened: 2007-11-11 12:48 0000
|
When creating a new database, a malicious user can use a client-side Web proxy
to place malicious code in the "db" parameter of the POST request. Since
db_create.php does not properly sanitize user-supplied input, an administrator
could face a persistent XSS attack when the database names are displayed.
Sample Exploit Code:
db=>%22%27><img%20src%3d%22javascript:alert(%27XSS%27)%22>
2.11.2.1 is now out to fix this issue
From ChangeLog
- (2.11.2.1) fixed possible SQL injection using database name
- (2.11.2.1) fixed possible XSS in database name,
thanks to Omer Singer, The DigiTrust Group
Latest version in portage is 2.11.1.1, here's a full ChangeLog from that
version
http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0
This is now CVE-2007-5977 and CVE-2007-5976
CVE-2007-6100 to the third issue.
Web-apps, please bump this package.
Added phpmyadmin-2.11.2.2 to the tree.
Targets: alpha amd64 hppa ppc ppc64 sparc x86
removed insecure version from the tree. webapps done here.
time for vote here. I vote NO.
Bah, wrong bug.
Voting NO and closing.
Does not affect current (2008.0) release. Removing release.