CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

phpMyAdmin controluser SQL Injection Vulnerability (PMASA-2016-19)——漏洞银行丨0DAY BANK

2016年8月25日 2149点热度 0人点赞 0条评论

漏洞类别:CGI

漏洞等级:

漏洞信息

phpMyAdmin is a free software tool written in PHP and intended to handle the administration of MySQL over the Internet.

A vulnerability was discovered in the libraries/central_columns.lib.php source file that allows an SQL injection attack to run arbitrary commands as the control user via a crafted database name that is mishandled in a central column query.

Affected Versions:
phpMyAdmin 4.6.x before 4.6.3
phpMyAdmin 4.4.x versions before 4.4.15.7

漏洞危害

Successful exploitation allows remote attackers to inject and execute arbitrary SQL code a targeted server.

解决方案

Users are advised to upgrade to phpMyAdmin 4.6.3, 4.4.15.7 or the latest version.

Patch:
Following are links for downloading patches to fix the vulnerabilities:

phpMyAdmin 4.6.3, 4.4.15.7

0day

标签: 暂无
最后更新:2016年10月22日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me