Paketname
phpMyAdmin
Datum
2009-01-23
Advisory ID
MDVSA-2009:026
Betroffene Versionen
CS4.0 x86_64 , CS4.0 i586

Problembeschreibung

Cross-site scripting (XSS) vulnerability in pmd_pdf.php allows
remote attackers to inject arbitrary web script or HTML by
using db script parameter when register_global php parameter is
enabled (CVE-2008-4775).

Cross-site request forgery (CSRF) vulnerability in tbl_structure.php
allows remote attackers perform SQL injection and execute arbitrary
code by using table script parameter (CVE-2008-5621).

Multiple cross-site request forgery (CSRF) vulnerabilities in allows
remote attackers perform SQL injection by using unknown vectors
related to table script parameter (CVE-2008-5622).

This update provide the fix for these security issues.

Aktualisierte Pakete

CS4.0 x86_64

 7589375efc20c24aec34469a8fcc05e8  corporate/4.0/x86_64/phpMyAdmin-2.11.9.4-0.1.20060mlcs4.noarch.rpm 
 fb84268bcbb158d12dbf17dade4c6007  corporate/4.0/SRPMS/phpMyAdmin-2.11.9.4-0.1.20060mlcs4.src.rpm

CS4.0 i586

 7589375efc20c24aec34469a8fcc05e8  corporate/4.0/i586/phpMyAdmin-2.11.9.4-0.1.20060mlcs4.noarch.rpm 
 fb84268bcbb158d12dbf17dade4c6007  corporate/4.0/SRPMS/phpMyAdmin-2.11.9.4-0.1.20060mlcs4.src.rpm

Referenzen