Package: phpmyadmin
Severity: critical
Tags: security

Hello,

As reported at
http://www.securityfocus.com/archive/1/419709/30/0/threaded
phpMyAdmin server_privileges.php is prone to SQL Injection
vulnerability. A remote attacker may execute arbitrary SQL command by
sending specially-crafted URI to server_privileges.php db_name or
checkprivs parameter.

Regards,
Neil McGovern
-- 
   __   
 .`  `. [EMAIL PROTECTED] | Application Manager
 : :' ! ---------------- | Secure-Testing Team member
 '. `-  gpg: B345BDD3    | Webapps Team member
   `-   Please don't cc, I'm subscribed to the list

Attachment: signature.asc
Description: Digital signature

Reply via email to