Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Aug 2005
    Posts
    29

    Default phpMyAdmin 2.6.4 and 2.6.4-pl1 Local file inclusion vulnerability

    Hi i read this and i want to know if we have to upgrade to the new verion of PHPMyAdmin 2.6.4-pl2:

    Announcement-ID: PMASA-2005-4
    Date: 2005-10-11

    Summary:
    Local file inclusion vulnerability

    Description:
    In libraries/grab_globals.lib.php, the $__redirect parameter was not correctly validated, opening the door to a local file inclusion attack.


    Severity:
    We consider this vulnerability to be serious. However, it can be exploited only on systems not running in PHP safe mode (unless a deliberate hole was opened by including in open_basedir some paths containing sensitive data).

    Affected versions:
    phpMyAdmin versions 2.6.4 and 2.6.4-pl1.

    Solution:
    Upgrade to phpMyAdmin 2.6.4-pl2 or newer.

  2. #2
    Member
    Join Date
    Mar 2002
    Location
    Alberta, Canada
    Posts
    1,509

    Default

    All depends on your Server security by the looks of things.

    Just more good reasons why always running PHP in 'safe_mode' and 'open_basedir' restrictions turned ON, just makes a whole lotta sense.
    Helping people Host, Create, and Maintain their Web Site
    Also providing Server Admin Services - setup / troubleshooting

    http://potentproducts.com/

  3. #3
    Member
    Join Date
    Aug 2005
    Posts
    29

    Default

    And how we know if really needs to do it? we try this bug...and works

    thanks

  4. #4
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    You need to follow the cPanel changelog, this has been incorporated into the release tree (have a look on http://layer1.cpanel.net).

    Do bear in mind that to run phpmyadmin that comes with cPanel you do need to have a valid cPanel login to access it.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  5. #5
    Member
    Join Date
    Mar 2005
    Location
    Ekaterinburg - Russia
    Posts
    56
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    phpMyAdmin 2.6.4-pl3 has been released with the following bugfix among others,
    Security fixes: local file inclusion and XSS
    http://www.phpmyadmin.net/home_page/...php?relnotes=0

    Vote for it on bugzilla so cPanel updates it
    http://bugzilla.cpanel.net/show_bug.cgi?id=3429

Similar Threads & Tags
Similar threads

  1. Replies: 10
    Last Post: 07-14-2011, 10:29 AM
  2. [Case 47031] phpMyAdmin security vulnerability
    By CoreISP.net in forum Database Discussions
    Replies: 8
    Last Post: 03-03-2011, 10:06 AM
  3. SECURITY ALERT: Horde arbitrary file inclusion vulnerability
    By ericgregory in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 03-06-2008, 11:10 PM
  4. SECURITY ALERT: Horde arbitrary file inclusion vulnerability
    By ericgregory in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 03-06-2008, 11:10 PM
  5. Security vulnerability: phpMyAdmin Cross-Site Scripting Vulnerabilities
    By iCARus in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 11-19-2004, 09:51 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube