FreeBSD : phpMyAdmin -- bypass 'no password' restriction (68611303-149e-11e7-b9bb-6805ca0b3d42)

high Nessus Plugin ID 99060

Language:

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

The phpMyAdmin team reports : Summary Bypass $cfg['Servers'][$i]['AllowNoPassword'] Description A vulnerability was discovered where the restrictions caused by $cfg['Servers'][$i]['AllowNoPassword'] = false are bypassed under certain PHP versions. This can allow the login of users who have no password set even if the administrator has set $cfg['Servers'][$i]['AllowNoPassword'] to false (which is also the default).

This behavior depends on the PHP version used (it seems PHP 5 is affected, while PHP 7.0 is not). Severity We consider this vulnerability to be of moderate severity. Mitigation factor Set a password for all users.

Solution

Update the affected package.

See Also

https://www.phpmyadmin.net/security/PMASA-2017-8/

http://www.nessus.org/u?2fa394f0

Plugin Details

Severity: High

ID: 99060

File Name: freebsd_pkg_68611303149e11e7b9bb6805ca0b3d42.nasl

Version: 3.4

Type: local

Published: 3/30/2017

Updated: 1/4/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:phpmyadmin, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 3/29/2017

Vulnerability Publication Date: 3/28/2017