oss-sec mailing list archives
Re: CVE request: phpMyAdmin < 3.1.1.0 (SQL injection through XSRF on several pages )
From: Tomas Hoger <thoger () redhat com>
Date: Wed, 17 Dec 2008 15:40:01 +0100
On Tue, 16 Dec 2008 20:52:42 -0500 (EST) "Steven M. Christey" <coley () linus mitre org> wrote:
Two separate CVE's are assigned, one for the original milw0rm exploit and the other for the unspecified vectors implied by the implied "XSRF on several pages" in the PMASA-2008-10 advisory.
Are those really separate issues? I believe that -5622 was assigned because of the following mention in the upstream ChangeLog: - [security] possible XSRF on several pages However, that ChangeLog entry was added as a not too good description of the fix for the SQL injection described in milw0rm 7382. Upstream commit is referenced in the PMASA-2008-10: http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin?view=rev&revision=12100 I think that the wording here is bit confusing. I think this kind of flaw would normally be described "privileged / logged-in user SQL injection". Though as this is SQL DB management application, once you are logged in, you can execute SQL commands using the standard application features, rather than having to find some privileged user SQL injection flaw. Hence this is only exploitable via CSRF-like methods. Not sure if the CSRF term is right there, as this "CSRF" does not seem to do any harm without SQL injection flaw. Or were there any other reasons for split? -- Tomas Hoger / Red Hat Security Response Team
Current thread:
- CVE request: phpMyAdmin < 3.1.1.0 (SQL injection through XSRF on several pages ) Hanno Böck (Dec 09)
- Re: CVE request: phpMyAdmin < 3.1.1.0 (SQL injection through XSRF on several pages ) Steven M. Christey (Dec 16)
- Re: CVE request: phpMyAdmin < 3.1.1.0 (SQL injection through XSRF on several pages ) Tomas Hoger (Dec 17)
- Re: CVE request: phpMyAdmin < 3.1.1.0 (SQL injection through XSRF on several pages ) Steven M. Christey (Dec 16)