Menu

#2144 Possibility to access phpmyadmin without proper credentials

2.8.0.3
invalid
nobody
5
2013-06-11
2006-05-12
Brecht Kets
No

When I 'logged on' with the username [ root" OR
1=1')-- ] and a blank password, I was able to gain
access to phpmyadmin. I got the same right's as
phpmyadmin uses to check credentials.

Cookie authentication was enabled.

Discussion

  • Brecht Kets

    Brecht Kets - 2006-05-12
    • priority: 5 --> 9
     
  • Michal Čihař

    Michal Čihař - 2006-05-12
    • priority: 9 --> 5
     
  • Michal Čihař

    Michal Čihař - 2006-05-12

    Logged In: YES
    user_id=192186

    I can not reproduce this. Well if this works it looks like
    bug rather in MySQL than in phpMyAdmin as phpMyAdmin only
    connects to MySQL with credentials you enter in login form.

     
  • Brecht Kets

    Brecht Kets - 2006-05-12
    • priority: 5 --> 9
     
  • Michal Čihař

    Michal Čihař - 2006-05-12
    • priority: 9 --> 5
     
  • Michal Čihař

    Michal Čihař - 2006-05-12

    Logged In: YES
    user_id=192186

    What MySQL version do you use and what php extensions (mysql
    or mysqli)?

     
  • Brecht Kets

    Brecht Kets - 2006-05-12
    • priority: 5 --> 9
     
  • Brecht Kets

    Brecht Kets - 2006-05-12

    Logged In: YES
    user_id=1521613

    for example: http://rabus.phpmyadmin.net/demos/RELEASE_FINAL/

    i use this one because it's one from phpmyadmin.net

    this site uses MySQL 5.0.20 with the mysqli extension.
    I use MySQL 5.0.20 with the mysql extension

     
  • Michal Čihař

    Michal Čihař - 2006-05-12
    • priority: 9 --> 5
    • status: open --> closed-invalid
     
  • Michal Čihař

    Michal Čihař - 2006-05-12

    Logged In: YES
    user_id=192186

    There was security bug in MySQL 5.0.20 on handling login
    names which has been fixed in 5.0.21 so I guess it is this
    issue (as I can not reproduce it on 5.0.21 but I can confirm
    it with 5.0.20).

     
  • Jürgen Wind

    Jürgen Wind - 2006-05-13

    Logged In: YES
    user_id=1383652

    http://rabus.phpmyadmin.net/demos/RELEASE_FINAL/
    works with any username, pw empty
    :)

     
  • Michal Čihař

    Michal Čihař - 2013-06-11
    • Status: closed-invalid --> invalid
     
MongoDB Logo MongoDB