Jul 24 2011

phpMyAdmin code execution vulnerability – 2011

Tag: Exploit,Security,Web Application SecurityThe-Wildcat @ 17:39

This is going to be a “phpMyAdmin code execution vulnerability” Blog :mrgreen: . No, seriously I’ve been really busy, working for new projects, the whole blabla story :mrgreen: .

But, I’ve recently found two LFI’s and one RCE and some XSS in phpMyAdmin’s latest versions: 3.4.0 – 3.4.3.1.

Because they did not include the link to my advisories, I’ll make them available here, enjoy :)

 

 

Need help securing your (web) applications? Write an e-mail to wildcat at the-wildcat dot de :mrgreen:

2 Responses to “phpMyAdmin code execution vulnerability – 2011”

  1. Debugger says:

    Since there is at least one critical unknown bug in every non trivial software and since open source means you can actually have a look into the code, there is no secure open source software, nor is there any other software that is…
    …not even wordpress :-P

    • The-Wildcat says:

      Especially not wordpress :D

      I’ve never expected phpMyAdmin to be secure, nor any other software. Opensource or not.
      That’s why I’m looking into opensource software, to help make it a bit more secure :)

Leave a Reply