PhpMyAdmin server_user_groups.php access Restriction Bypass Vulnerability
Release date:
Updated on:
Affected Systems:
PhpMyAdmin <4.2.6
PhpMyAdmin <4.1.14.2
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-4987
Phpmyadmin is an online management tool for MySQL databases. Its main functions include creating data tables online, running SQL statements, searching and querying data, and importing and exporting data.
In phpMyAdmin versions earlier than phpMyAdmin 4.1.14.2 and 4.2.6, server_user_groups.php has a security vulnerability. authenticated remote users use viewUsers requests to bypass target access restrictions and read the MySQL user list.
<* Source: Chirayu Chiripal
Link: http://www.phpmyadmin.net/home_page/security/PMASA-2014-7.php
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PhpMyAdmin
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://github.com/phpmyadmin/phpmyadmin/commit/395265e9937beb21134626c01a21f44b28e712e5
Https://github.com/phpmyadmin/phpmyadmin/commit/45550b8cff06ad128129020762f9b53d125a6934
Http://www.phpmyadmin.net/home_page/security/
Install the LAMP \ Vsftpd \ Webmin \ phpMyAdmin service and settings in Ubuntu 13.04
Example of LAMP architecture collaborative application-phpMyAdmin
PhpMyAdmin and Wordpress for LAMP applications
PhpMyAdmin logon timeout Solution
Install phpMyAdmin and Adminer in Ubuntu
Implement SSL functions based on LAMP and install phpMyAdmin
PhpMyAdmin details: click here
PhpMyAdmin: click here
This article permanently updates the link address: