FreeBSD : phpMyAdmin -- multiple vulnerabilities (cd68ff50-362b-11e0-ad36-00215c6a37bb)

high Nessus Plugin ID 51965

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

phpMyAdmin team reports :

It was possible to create a bookmark which would be executed unintentionally by other users.

When the files README, ChangeLog or LICENSE have been removed from their original place (possibly by the distributor), the scripts used to display these files can show their full path, leading to possible further attacks.

Solution

Update the affected packages.

See Also

https://www.phpmyadmin.net/security/PMASA-2011-2/

https://www.phpmyadmin.net/security/PMASA-2011-1/

http://www.nessus.org/u?fb439f2f

Plugin Details

Severity: High

ID: 51965

File Name: freebsd_pkg_cd68ff50362b11e0ad3600215c6a37bb.nasl

Version: 1.9

Type: local

Published: 2/14/2011

Updated: 1/6/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:phpmyadmin, p-cpe:/a:freebsd:freebsd:phpmyadmin211, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 2/11/2011

Vulnerability Publication Date: 2/8/2011