High Security Risk in Ver. phpwcms 1.1-RC2_2004-01-10a
High Security Risk in Ver. phpwcms 1.1-RC2_2004-01-10a
Security Bug Report
Risk: VERY HIGH
Report Date: 10-01-2004 17:19 CET
Expected Version: phpwcms 1.1-RC2_2004-01-10a AND up
Affected spot: phpMyAdmin
Location of the spot: ./include/inc_ext/phpMyAdmin/<all data within>
Status: pending
Summary:
The phpmyadmin directory is NOT secured by the 'checklogin.inc.php' which is included by the phpwcms.php which controlls the adminrights within the admin menue. Anyone on the web who knows about the struckture behind phpwcms can access the directory by typing in his browser the URL http://yoururl.tld/include/inc_ext/phpMyAdmin/. He will easyly access the mySQL Database which stores ALL DATA for phpwcms and is allowed to change and/or delete content.
Workaround:
Install the Patch: http://osdn.dl.sourceforge.net/sourcefo ... 01-10b.zip
Recommendation:
Install the security bugfix.
Risk: VERY HIGH
Report Date: 10-01-2004 17:19 CET
Expected Version: phpwcms 1.1-RC2_2004-01-10a AND up
Affected spot: phpMyAdmin
Location of the spot: ./include/inc_ext/phpMyAdmin/<all data within>
Status: pending
Summary:
The phpmyadmin directory is NOT secured by the 'checklogin.inc.php' which is included by the phpwcms.php which controlls the adminrights within the admin menue. Anyone on the web who knows about the struckture behind phpwcms can access the directory by typing in his browser the URL http://yoururl.tld/include/inc_ext/phpMyAdmin/. He will easyly access the mySQL Database which stores ALL DATA for phpwcms and is allowed to change and/or delete content.
Workaround:
Install the Patch: http://osdn.dl.sourceforge.net/sourcefo ... 01-10b.zip
Recommendation:
Install the security bugfix.
Last edited by Florian on Sat 10. Jan 2004, 19:21, edited 1 time in total.
- Oliver Georgi
- Site Admin
- Posts: 9919
- Joined: Fri 3. Oct 2003, 22:22
- Contact:
- Oliver Georgi
- Site Admin
- Posts: 9919
- Joined: Fri 3. Oct 2003, 22:22
- Contact:
well therefor it is nice with a big forumOliver Georgi wrote:Is solved. (I hope)
Sorry!
regards
Oliver

http://www.studmed.dk Portal for doctors and medical students in Denmark
yeah and maybe a mailing list?Florian wrote:Mybe we should set up a "Bugbuster" like written above by me for further Bug, which "maybe" appers (of corse I don't hope). So we can do a quick bugfix and everybody knows what to do.
Cheers,
Florian
so you automatic rezeive bug repports ? right now you only rezeive a email if you have created or replyed to the topic....!!
Eg, you could install this mod - it let you receive mails when there are new posts in a given forum....it is still a alpha mod but.....
http://www.netclectic.com/forums/viewtopic.php?t=4402
http://www.studmed.dk Portal for doctors and medical students in Denmark
- Oliver Georgi
- Site Admin
- Posts: 9919
- Joined: Fri 3. Oct 2003, 22:22
- Contact:
Cet, what do you think is not solved?
Try this:
1) Close all browser windows - maybe logoff backend
2) Then try to open again: http://www.myphpwcms.com/include/inc_ext/phpMyAdmin
What happens?
Oliver
Try this:
1) Close all browser windows - maybe logoff backend
2) Then try to open again: http://www.myphpwcms.com/include/inc_ext/phpMyAdmin
What happens?
Oliver
- Oliver Georgi
- Site Admin
- Posts: 9919
- Joined: Fri 3. Oct 2003, 22:22
- Contact:
- Oliver Georgi
- Site Admin
- Posts: 9919
- Joined: Fri 3. Oct 2003, 22:22
- Contact:
Can somebody with still existing security problems test the following new patch file
http://www.phpwcms.de/docu/config.inc.developer.zip
extract and put it into:
include/inc_ext/phpMyAdmin
It uses same authentication check as phpwcms itself.
Regards
Oliver
http://www.phpwcms.de/docu/config.inc.developer.zip
extract and put it into:
include/inc_ext/phpMyAdmin
It uses same authentication check as phpwcms itself.
Regards
Oliver
Oliver,
I think it is working now ....I did two tests.
1) on a new pc (kids pc ..never used phpwcms on that system before).
a direct link to phpmyadmin redirects to the root of the domain ...
2) another pc. Logged into backend and started phpmyadmin. Then logged out and made a direct link to phpmyadmin. Again I was redirected to the root of the domain.
Johan.
I think it is working now ....I did two tests.
1) on a new pc (kids pc ..never used phpwcms on that system before).
a direct link to phpmyadmin redirects to the root of the domain ...
2) another pc. Logged into backend and started phpmyadmin. Then logged out and made a direct link to phpmyadmin. Again I was redirected to the root of the domain.
Johan.