Vigil@nce: phpMyAdmin, Cross Site Scripting of db
July 2009 by Vigil@nce
An attacker can use the db parameter to generate a Cross Site Scripting in phpMyAdmin.
Severity: 2/4
Consequences: client access/rights
Provenance: document
Means of attack: 1 attack
Ability of attacker: technician (2/4)
Confidence: unique source (2/5)
Diffusion of the vulnerable configuration: high (3/3)
Creation date: 01/07/2009
IMPACTED PRODUCTS
Unix - plateform
DESCRIPTION OF THE VULNERABILITY
The phpMyAdmin server is used to administer a MySQL database via a web browser.
The "db" parameter indicates the name of the database. This parameter is checked by phpMyAdmin. However, this check is bypassed if "db" starts with a double escape such as : ">’>
An attacker can therefore use the db parameter to generate a Cross Site Scripting in phpMyAdmin.
CHARACTERISTICS
Identifiers: BID-35531, VIGILANCE-VUL-8832
http://vigilance.fr/vulnerability/phpMyAdmin-Cross-Site-Scripting-of-db-8832





News





