Forum Moderators: coopster

Message Too Old, No Replies

PHPMyAdmin vulnerabilities

time to upgrade

         

jatar_k

8:06 pm on Dec 6, 2005 (gmt 0)

WebmasterWorld Administrator 10+ Year Member



[securityfocus.com...]

seems they released version 2.7.0 to address these issues

upgrade time as I know a lot of people here use it

ergophobe

6:39 pm on Dec 7, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Sounds bad on the face of it, but since PhpMyAdmin is usually behind some authentication layer which gives access to all sorts of site information (like CPanel with a file manager and all), by the time someone gets to the point of being able to inject XSS into your PhpMyAdmin install, they can probably do almost anything they please to your DB or your site in general.

It seems like XSS vulnerabilities in this case would be less to worry about than in others. Am I missing something?

jatar_k

6:41 pm on Dec 7, 2005 (gmt 0)

WebmasterWorld Administrator 10+ Year Member



no, I thought the same but figured it was worth a mention

I have this image in my mind like open logs, I bet there are open phpmyadmins as well. This being the case I think the least of your worries is whether they can exploit it via XSS but that they could could one click drop the whole thing.