phpMyAdmin < 2.5.2 Multiple Vulnerabilities

medium Nessus Network Monitor Plugin ID 2420

Synopsis

The remote web server contains a PHP application that is affected by multiple vulnerabilities.

Description

The remote host is running phpMyAdmin, an open-source software written in PHP to handle the administration of MySQL over the Web.
The remote version of this software is vulnerable to several flaws :
- It may be tricked into disclosing the physical path of the remote PHP installation
- It is vulnerable to cross-site scripting, which may allow an attacker to steal the cookies of your users
- It is vulnerable to a flaw that may allow an attacker to list the content of arbitrary directories on the remote server.
An attacker may use these flaws to gain more knowledge about the remote host and therefore set up more complex attacks against it.

Solution

Upgrade to phpMyAdmin 2.5.2 or higher.

See Also

http://www.securityfocus.com/archive/1/325641

http://www.securityfocus.com/archive/1/327511

Plugin Details

Severity: Medium

ID: 2420

Family: CGI

Published: 11/22/2004

Updated: 3/6/2019

Nessus ID: 11761

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 4.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 5.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:phpmyadmin:phpmyadmin

Reference Information

BID: 7963, 7964, 7965, 7962