phpMyAdmin < 2.5.2 Multiple Vulnerabilities

medium Nessus Plugin ID 11761

Language:

Synopsis

The remote web server contains a PHP application that suffers from multiple vulnerabilities.

Description

The remote host is running a version of phpMyAdmin that is vulnerable to several attacks :

- It may be tricked into disclosing the physical path of the remote PHP installation.

- It is vulnerable to cross-site scripting that could allow an attacker to steal the cookies of your users.

- It is vulnerable to a flaw that could allow an attacker to list the contents of arbitrary directories on the remote server.

An attacker could use these flaws to gain more knowledge about the remote host and therefore set up more complex attacks against it.

Solution

Upgrade to phpMyAdmin 2.5.2 or later.

See Also

https://www.securityfocus.com/archive/1/325641

https://www.securityfocus.com/archive/1/327511

Plugin Details

Severity: Medium

ID: 11761

File Name: phpMyAdmin_multiple_flaws.nasl

Version: 1.31

Type: remote

Family: CGI abuses

Published: 6/18/2003

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Vulnerability Information

CPE: cpe:/a:phpmyadmin:phpmyadmin

Required KB Items: www/PHP, www/phpMyAdmin

Excluded KB Items: Settings/disable_cgi_scanning

Exploit Available: true

Exploit Ease: No exploit is required

Vulnerability Publication Date: 6/18/2003

Reference Information

BID: 7962, 7963, 7964, 7965