Thread: Security Alert
View Single Post
Old 10-11-2005, 09:14 AM  
ServerGenius
Confirmed User
 
Join Date: Feb 2002
Location: Amsterdam
Posts: 9,377
Security Alert

Hello everybody,

phpmyadmin-2.6.4-pl1.pl and all previous version contain a security hole.

Due to an error in grab_globals.lib.php it's possible to execute the command
'subform[][redirect]' in any form to see the contents of files outside the webroot.

I suggest to upgrade this as soon as possible as this is a quite serious
security hole.

See Sig!
__________________
| http://www.sinnerscash.com/ | ICQ: 370820 | Skype: SinnersCash | AdultWhosWho |
ServerGenius is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote