New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
sql injection in /phpmyadmin/libraries/classesCreateAddField.php #15898
Comments
|
We’ll investigate this and work on an expedited fix.
It’s common to alert a project privately when there is a potential security
matter so that a proper fix can be prepared and tested before the details
of the vulnerability are made public. In fact, when creating the issue here
on GitHub, we provide a series of prompts to help guide properly reporting
these issues.
|
|
Can I work on this issue? @ibennetch |
|
Sure, Bismita. I’m not sure in which branch this first appears, but a fix should target QA_4_9 if applicable.
|
|
sorry about the issues,i don't know about it. How i can contact security team? contact email "security@phpmyadmin.net"? |
|
Yes, that's correct; we prefer to use that email address for security matters. Thank you for your report; we'll keep you posted either here or through email regarding any release that will fix this. Best wishes. |
|
method |
Depends on 20e3d2f Signed-off-by: William Desportes <williamdes@wdes.fr>
|
I made a proposal in #16004 |
…gine argument Pull-request: phpmyadmin#16004 Fixes: phpmyadmin#15898 Security: ca42395 Ref: phpmyadmin#16004 Ref: phpmyadmin#15898 For now I do not have a CVE code for this one. Signed-off-by: William Desportes <williamdes@wdes.fr>
Ref: e1f5dfc Signed-off-by: William Desportes <williamdes@wdes.fr>
|
@ibennetch did you know we had a CVE for this one ? Introduced by 4d98851 |
Signed-off-by: William Desportes <williamdes@wdes.fr> (cherry picked from commit ca42395)
Describe the bug
To Reproduce
Steps to reproduce the behavior:
tbl_storage_engineortbl_collationExpected behavior
https://www.slideshare.net/OWASPEEE/russia-mysql-oob-injections
Screenshots
-adding

'in paramtbl_storage_engine-- -Server configuration
Client configuration
The text was updated successfully, but these errors were encountered: