Menu

#436 adminer username xss

4.1.0
closed-fixed
nobody
XSS (2)
9
2015-02-07
2015-01-30
zeng zhen
No

there is one xss security on "username" param
When access url like demo.adminer.org/adminer.php?username=root,one attacter can inject script codes like -> demo.adminer.org/adminer.php?username=root''><scRipt>alert('xss')</sCript>
I think it is really bad.
server is php5.6.4&mysql5.6.12

Discussion

  • Jakub Vrána

    Jakub Vrána - 2015-02-03

    This is a very serious bug, thank you for the report. I'll fix it and release a new version of Adminer this week.

    Please mark security bugs as private the next time.

     
    • zeng zhen

      zeng zhen - 2015-02-04

      thank you for response .I'll mark private bugs private next time(wish never will have next time).

       
  • Jakub Vrána

    Jakub Vrána - 2015-02-03
    • status: open --> open-accepted
    • private: No --> Yes
     
  • Jakub Vrána

    Jakub Vrána - 2015-02-07

    Fixed and released, thank you again for this report.

     
  • Jakub Vrána

    Jakub Vrána - 2015-02-07
    • status: open-accepted --> closed-fixed
    • private: Yes --> No
     

Log in to post a comment.

Want the latest updates on software, tech news, and AI?
Get latest updates about software, tech news, and AI from SourceForge directly in your inbox once a month.