phpMyAdmin¿çÕ¾ÒªÇóαÔì·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-09-23

¡ñ·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-12922 £¬Î£ÏÕ¼¶±ð£ºÖÐΣ £¬CVSS·ÖÖµ£º6.5


¡ñÓ°Ïì°æ±¾


phpMyAdmin<= 4.9.0.1


¡ñ·ì϶¸ÅÊö


phpMyAdminÊÇÒ»¸öMySQLºÍMariaDBÊý¾Ý¿âµÄÃâ·Ñ¿ªÔ´ÖÎÀí¹¤¾ß £¬¿í·ºÓÃÓÚÖÎÀíWordPress¡¢JoomlaºÍºÜ¶àÆäËûÄÚÈÝÖÎÀíÆ½Ì¨´´½¨µÄÍøÕ¾µÄÊý¾Ý¿â¡£


½üÈÕ £¬°²È«×êÑÐÈËÔ±Manuel Garcia CardenasÅû¶ÁËphpMyAdminµÄÒ»¸ö¿çÕ¾ÒªÇóαÔ죨CVE-2019-12922£©·ì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÓÕʹÈÏÖ¤Óû§Ö´ÐжñÒâ²Ù×÷¡£µ±¹¥»÷Õß½«¶ñÒâ»ú¹ØµÄURL·¢Ë͸øÖ¸±êwebÖÎÀíԱʱ £¬Èô¸ÃwebÖÎÀíÔ±ÒÑʹÓÃͳһä¯ÀÀÆ÷µÇ½ÁËphpmyAdminÃæ°å £¬²¢´ò¿ª¸ÃÁ´½Ó £¬¼´¿ÉÖ´ÐÐURLÔ̺¬µÄ¶ñÒâÒªÇóɾ³ýÖ¸±ê·þÎñÆ÷ÉÏphpMyAdminÃæ°åÉèÖÃÒ³ÃæÖÐËùÅäÖõķþÎñÆ÷¡£


¡ñ·ì϶ÑéÖ¤


POC:ÀûÓà CSRF ¡ªÉ¾³ýÖ÷·þÎñÆ÷¡£


<p>Deleting Server 1</p>

<img src="

http://server/phpmyadmin/setup/index.php?page=servers&mode=remove&id=1";

style="display:none;" />


¡ñ½¨¸´½¨Òé


¹Ù·½ÔÝδ°ä²¼Õë¶Ô´Ë·ì϶µÄ½¨¸´°æ±¾¡£


һʱ»º½â´ëÊ©£º


Óû§¿Éͨ¹ýÔÚÿ´ÎŲÓÃʱʹÓÃtoken±äÁ¿ÑéÖ¤À´¶Ô¸Ã·ì϶½øÐзÀ»¤¡£


ÔÚÊØ»¤ÈËÔ±¶Ô¸Ã·ì϶½øÐн¨¸´Ç° £¬Ç¿ÁÒ½¨ÒéÓйصÄÓû§Ô¤·Àµã»÷ÈκοÉÒɵÄÁ´½ÓÔì³É·çÏÕ £¬Çë¹Ø×¢¹Ù·½ÓйØÐÂÎÅ £¬ÒÔ±ãʵʱÉý¼¶phpMyAdminÖÁ½¨¸´°æÕý±¾·À»¤´Ë·ì϶¡£


¡ñ²Î¿¼Á´½Ó


https://thehackernews.com/2019/09/phpmyadmin-csrf-exploit.html

https://seclists.org/fulldisclosure/2019/Sep/23