oss-sec mailing list archives
Re: Re: CVE for Wordpress plugin Portable-phpmyadmin
From: Anant Shrivastava <anant () anantshri info>
Date: Wed, 23 Oct 2013 08:30:05 +0530
Exactly, You request the proper url and it lets you in as well as let you perform all database level operations available on that specific file. some sample screenshots should clear the issue (attached for reference). [while phpmyadmin requires a valid userid and password for mysql db these credentials are pulled from wp-config.php (wordpress config fle) file directly in this plugin] Besides these two, there are a large number of full path disclosure on the whole project also however as wordpress itself doesn't consider that as a security issue rather mark it as a configuration issue ( http://codex.wordpress.org/Security_FAQ#Why_are_there_path_disclosures_when_directly_loading_certain_files.3F) Hence those are not reported. Anant Shrivastava GWAPT | CEH | RHCE Mob : 91-9880166033 E-mail : anant () anantshri info Web : http://anantshri.info On Wed, Oct 23, 2013 at 7:17 AM, Kurt Seifried <kseifried () redhat com> wrote:
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On 10/22/2013 02:13 PM, security curmudgeon wrote:: Thanks, please use CVE-2013-4454 for this issue. Which issue Kurt? The original post had phpinfo disclosure, and an auth bypass issue affecting multiple scripts.Sorry wrote the email in draft, then got distracted and sent it. The CVE is for the phpinfo() issue. Also a question: security bypass means what exactly? you simply request the file directly and it lets you in? - -- Kurt Seifried Red Hat Security Response Team (SRT) PGP: 0x5E267993 A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.15 (GNU/Linux) iQIcBAEBAgAGBQJSZyqyAAoJEBYNRVNeJnmTJNgP+wQS2NxvYsUUM0urirrf9vrv iKyJX+7J0QpGihtOesawYjkQDkAe8TjiE7RrSRUqw9I6Y7B1XCeo8afp25AS81Oq P82LKgVidTAEZuvzFjD7jG6w2ouXL0/idqpBkxwMCKlniUkUHwkhkLztXFHL6fAt qk2WVx/vSxg4eO9OXMymbbBlREX5XB/gaM3i0JV/Nlr1PXNIXF9n1rTn0Co7uWWU fToPmC8ekREkb3xWIpOrFrjg7ZsOR1QPlz1K132jAZPYSRVlxPgWUq0yXZqziz41 Ez2u9REOVM9u4Jazts1AYBhmHc34K2IYDKZWrpGNaS65drf3E11YarBCa+xH2HJT rJf/gzPPHtUOx75Gh79RDgv4i9M7Nit60f+4aE6tbsg8osaRg8PgFx7g9hdgf+TJ C8fWNyEA8rBp/WAOZY0Y33zLtlxsV0bECPT/lL3ltbtXEc9aw7hz3wFA4+6bKm2N PehG2qJwnwoLODzB3fqByZJi5b4lv8Dq72NVKvuFYQ4sqzzbmtZ0sslt7x/qFNyW MP1vpo3GZvNB/9R36j5dd2WG0fZG1p8VXp3FtYMemGYcWDt5zCWLK/uVCck33VK1 Z8nFfjFdAG8CRser9HZuyQ4MlTL0NxHkZpJK2fFuSJHrUKniFdmm9GjL3yBfa/MJ tEbbhAOkReaqTRtK0by8 =Jxc0 -----END PGP SIGNATURE-----
Current thread:
- CVE for Wordpress plugin Portable-phpmyadmin Anant Shrivastava (Oct 21)
- Re: CVE for Wordpress plugin Portable-phpmyadmin Kurt Seifried (Oct 21)
- Re: CVE for Wordpress plugin Portable-phpmyadmin Anant Shrivastava (Oct 21)
- Re: CVE for Wordpress plugin Portable-phpmyadmin Kurt Seifried (Oct 21)
- Re: CVE for Wordpress plugin Portable-phpmyadmin Anant Shrivastava (Oct 21)
- <Possible follow-ups>
- Re: CVE for Wordpress plugin Portable-phpmyadmin security curmudgeon (Oct 22)
- Re: Re: CVE for Wordpress plugin Portable-phpmyadmin Kurt Seifried (Oct 22)
- Re: Re: CVE for Wordpress plugin Portable-phpmyadmin Anant Shrivastava (Oct 22)
- Re: Re: CVE for Wordpress plugin Portable-phpmyadmin Kurt Seifried (Oct 23)
- Re: Re: CVE for Wordpress plugin Portable-phpmyadmin Kurt Seifried (Oct 22)
- Re: CVE for Wordpress plugin Portable-phpmyadmin Kurt Seifried (Oct 21)