Ones and Zeros
October 16, 2009, 8:44 AM

phpMyAdmin Plugs SQL Injection, XSS Flaws

A new version of phpMyAdmin has been released to plug two serious security holes that could lead to SQL injection and cross-site scripting attacks.

According to an advisory from the maintainers of the open-source tool, one of the vulnerabilities allow remote hackers to inject arbitrary web script or HTML via a crafted MySQL table name.

The second issue is a SQL injection vulnerability that allows remote attackers to inject SQL via various interface parameters of the PDF schema generator feature.

phpMyAdmin is an open source tool written in PHP intended to handle the administration of MySQL over the Web.

The group urged all users to upgrade to phpMyAdmin 3.2.2.1 or 2.11.9.6 immediately.

 

Blogger Bio

About Ones and Zeros

Ryan Naraine is a security writer social media enthusiast specializing in Internet and computer security issues. He also blogs at ZDNet and previously served as Editor-at-Large/Security at eWEEK and senior editor at Jupiter Media's internetnetnews.com. On this blog, Ryan provides in-depth coverage of hacker attacks, vulnerability research, flaw warnings and news analysis. Follow Ryan on Twitter.

Contact Ryan

 

Stay Connected