Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 87952
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Luke Macken (RETIRED) <lewk@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
phpmyadmin-2.6.2_rc1.ebuild.patch phpMyAdmin 2.6.2-rc1 ebuild patch patch Jakub Moc (RETIRED) 2005-04-08 07:55 0000 419 bytes Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 87952 depends on: Show dependency tree
Bug 87952 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-04-04 13:06 0000
==========================================================
Title: phpMyAdmin Cross-site Scripting Vulnerability

Application: phpMyAdmin
Vendor: http://www.phpmyadmin.net
Vulnerable Versions: <=2.6.2-beta1
Corrected: phpMyAdmin versions after 2.6.2-beta1
Bug: Cross-site Scripting
Date: 3-Apr-2005

Author: Oriol Torrent Santiago < oriol.torrent@gmail.com >

==========================================================

1) Background
   -----------
 phpMyAdmin is a tool written in PHP intended to handle the administration
 of MySQL over the Web. Currently it can create  and drop databases,
 create/drop/alter tables, delete/edit/add fields, execute any SQL statement,
 manage keys on fields,  manage privileges,export data into various formats
 and is available in 47 languages.


2) Problem description
   --------------------

 phpMyAdmin <=2.6.2-beta1 contain a vulnerability is caused due to
 missing validation of input supplied to "convcharset" variable.

 This can be exploited to execute arbitrary HTML and script code(JavaScript,
 VBScript,etc.) in a user's browser session in context of a vulnerable site.
 It allows an attacker to use the vulnerability to compromise the phpMyAdmin
 account, cookie theft, etc.


 Ex1:
 http://host/phpmyadmin/index.php?pma_username=&pma_password=&server=1&lang=en-iso-8859-1&convcharset=\"><script>alert(document.cookie)</script>

 Ex2:
 http://host/phpmyadmin/index.php?pma_username=&pma_password=&server=1&lang=en-iso-8859-1&convcharset=\"><h1>XSS</h1>

3) Solution:
   ---------

 Vendor was contacted on the 29th of March 2005 and new version is released
  
 Download the latest version of phpMyAdmin


4) Timeline
   --------

29/03/2005  Bug discovered
29/03/2005  Vendor notified
29/03/2005  Vendor response and bug fixed
03/04/2005  New version released
03/04/2005  Advisory released

------- Comment #1 From Luke Macken (RETIRED) 2005-04-04 13:09:08 0000 -------
twp, please bump.

------- Comment #2 From Jakub Moc (RETIRED) 2005-04-08 07:55:51 0000 -------
Created an attachment (id=55674) [details]
phpMyAdmin 2.6.2-rc1 ebuild patch

Someone please bump. ;-)

------- Comment #3 From Aaron Walker (RETIRED) 2005-04-08 09:20:26 0000 -------
> Someone please bump. ;-)
sure.

Stable on x86. CC'd archs please stabilize.

------- Comment #4 From Michael Hanselmann (hansmi) (RETIRED) 2005-04-08 10:24:28 0000 -------
Stable on ppc.

------- Comment #5 From Bryan Østergaard (RETIRED) 2005-04-08 11:32:48 0000 -------
Alpha stable.

------- Comment #6 From Guy Martin 2005-04-08 12:26:47 0000 -------
Stable on hppa.

------- Comment #7 From Gustavo Zacarias (RETIRED) 2005-04-08 17:55:29 0000 -------
sparc stable.

------- Comment #8 From Simon Stelling (RETIRED) 2005-04-09 04:13:24 0000 -------
amd64 done

------- Comment #9 From Thierry Carrez (RETIRED) 2005-04-09 04:56:49 0000 -------
Security please vote on GLSA need

------- Comment #10 From Thierry Carrez (RETIRED) 2005-04-10 09:51:54 0000 -------
We issued a Low GLSA for previous XSS things in phpmyadmin (200411-36), and
phpmyadmin team finds the issue serious, so I think we should do one. so YES

------- Comment #11 From Luke Macken (RETIRED) 2005-04-10 16:15:52 0000 -------
I vote YES as well.

2 YES votes == A GLSA will be released for this issue.

------- Comment #12 From Luke Macken (RETIRED) 2005-04-11 12:18:50 0000 -------
GLSA 200504-08

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug