Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
PHPNuke seems to have a horrible security track record, but continues to be quite popular. No statement from the PHPNuke folks yet, but if you're using a rapid site development tool, don't forget to consider the security implications. "Cross site . . . . PHPNuke seems to have a horrible security track record, but continues to be quite popular. No statement from the PHPNuke folks yet, but if you're using a rapid site development tool, don't forget to consider the security implications. "Cross site scripting is a serious problem, (even if some people doesn't believe it), On this second round i'll show 8 new XSS vulnerabilities in PHP Nuke (most of them are also path disclosure vulns):" Date: 23 Apr 2002 09:50:48 +0200 From: "Replugge [ROD]" To:
The phpMyAdmin developers have announced the release of version 3.3.9.1 and 2.11.11.2 of their database administration tool, security updates that fix a path disclosure vulnerability. According to the developers, when the README, ChangeLog or LICENSE files are removed from their original location, the scripts used to display these files can show their full path, possibly leading to further attacks.. All versions previous to 3.3.9.1 and 2.11.11.2 are said to be affected. While the developers consider the vulnerability to be non-critical, they still advise all users to upgrade as soon as possible. Alternatively, users can apply the provided patches. The link for this article located at H Security is no longer available. . The maintainers of phpMyAdmin have released new versions 3.3.9.1 and 2.11.11.2 to address a critical path disclosure vulnerability. Users are advised to upgrade promptly!. phpMyAdmin Security, Database Tool Fix, Path Exposure Issue. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.