[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Tue, 15 Jul 2008 21:00:55 +0200
From: Hanno Böck <hanno@...eck.de>
To: oss-security@...ts.openwall.com
Cc: coley@...re.org
Subject: CVE request: phpmyadmin < 2.11.7.1
http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0
From Changelog:
- protection against XSS when register_globals is on and .htaccess
has no effect, thanks to Tim Starling
- (2.11.7.1) [security] XSRF/CSRF by manipulating the db,
convcharset and collation_connection parameters,
thanks to YGN Ethical Hacker Group
--
Hanno Böck Blog: http://www.hboeck.de/
GPG: 3DBD3B20 Jabber/Mail: hanno@...eck.de
[ CONTENT OF TYPE application/pgp-signature SKIPPED ]
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Powered by Openwall GNU/*/Linux -
Powered by OpenVZ