Explore top 10 tips to secure your open-source projects now. Read More
×
It was discovered there was a potential remote code execution vulnerability in phppgadmin, a web-based administration tool for the PostgreSQL database server. This issue concerned the deserialisation of untrusted data which may have led to remote code execution because . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3644-1
phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area, database.php does not verify the source of an HTTP request. This can be leveraged by a remote attacker to trick a logged-in administrator to visit a malicious page with a CSRF exploit and execute arbitrary system commands on the . MGASA-2021-0074 - Updated phppgadmin package fixes a security vulnerability Publication date: 08 Feb 2021 URL: https://advisories.mageia.org/MGASA-2021-0074.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-10784 phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area, database.php does not verify the source of an HTTP request. This can be leveraged by a remote attacker to trick a logged-in administrator to visit a malicious page with a CSRF exploit and execute arbitrary system commands on the server (CVE-2019-10784). References: - https://bugs.mageia.org/show_bug.cgi?id=27912 - https://www.cve.org/CVERecord?id=CVE-2019-10784 SRPMS: - 7/core/phppgadmin-7.13.0-1.mga7 . MGASA-2021-0075 addresses a vital security vulnerability in phpMyAdmin enabling potential XSS exploits from external actors.. phppgadmin, CSRF, Mageia 7, security update, remote exploit. . Severity: Critical. LinuxSecurity.com Team
A vulnerability has been discovered in phppgadmin, a set of PHP scripts to administrate PostgreSQL over the WWW, that can lead to disclose sensitive information. Successful exploitation requires that "magic_quotes_gpc" is disabled.. - --------------------------------------------------------------------------Debian Security Advisory DSA 759-1
Get the latest Linux and open source security news straight to your inbox.