phpMyAdmin¿çÕ¾ÇëÇóαÔìÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-09-23

¡ñÎó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-12922£¬£¬£¬£¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬ £¬£¬£¬£¬CVSS·ÖÖµ£º6.5


¡ñÓ°Ïì°æ±¾


phpMyAdmin<= 4.9.0.1


¡ñÎó²î¸ÅÊö


phpMyAdminÊÇÒ»¸öMySQLºÍMariaDBÊý¾Ý¿âµÄÃâ·Ñ¿ªÔ´ÖÎÀí¹¤¾ß£¬£¬£¬£¬ £¬£¬£¬£¬ÆÕ±éÓÃÓÚÖÎÀíWordPress¡¢JoomlaºÍÐí¶àÆäËûÄÚÈÝÖÎÀíÆ½Ì¨½¨ÉèµÄÍøÕ¾µÄÊý¾Ý¿â¡£¡£¡£


¿ËÈÕ£¬£¬£¬£¬ £¬£¬£¬£¬Çå¾²Ñо¿Ö°Ô±Manuel Garcia CardenasÅû¶ÁËphpMyAdminµÄÒ»¸ö¿çÕ¾ÇëÇóαÔ죨CVE-2019-12922£©Îó²î¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÓÕʹÈÏÖ¤Óû§Ö´ÐжñÒâ²Ù×÷¡£¡£¡£µ±¹¥»÷Õß½«¶ñÒâ½á¹¹µÄURL·¢Ë͸øÄ¿µÄwebÖÎÀíԱʱ£¬£¬£¬£¬ £¬£¬£¬£¬Èô¸ÃwebÖÎÀíÔ±ÒÑʹÓÃͳһä¯ÀÀÆ÷Éϰ¶ÁËphpmyAdminÃæ°å£¬£¬£¬£¬ £¬£¬£¬£¬²¢·­¿ª¸ÃÁ´½Ó£¬£¬£¬£¬ £¬£¬£¬£¬¼´¿ÉÖ´ÐÐURL°üÀ¨µÄ¶ñÒâÇëÇóɾ³ýÄ¿µÄЧÀÍÆ÷ÉÏphpMyAdminÃæ°åÉèÖÃÒ³ÃæÖÐËùÉèÖõÄЧÀÍÆ÷¡£¡£¡£


¡ñÎó²îÑéÖ¤


POC:ʹÓà CSRF ¡ªÉ¾³ýÖ÷ЧÀÍÆ÷¡£¡£¡£


<p>Deleting Server 1</p>

<img src="

http://server/phpmyadmin/setup/index.php?page=servers&mode=remove&id=1";

style="display:none;" />


¡ñÐÞ¸´½¨Òé


¹Ù·½ÔÝδÐû²¼Õë¶Ô´ËÎó²îµÄÐÞ¸´°æ±¾¡£¡£¡£


ÔÝʱ»º½â²½·¥£º


Óû§¿Éͨ¹ýÔÚÿ´ÎŲÓÃʱʹÓÃtoken±äÁ¿ÑéÖ¤À´¶Ô¸ÃÎó²î¾ÙÐзÀ»¤¡£¡£¡£


ÔÚά»¤Ö°Ô±¶Ô¸ÃÎó²î¾ÙÐÐÐÞ¸´Ç°£¬£¬£¬£¬ £¬£¬£¬£¬Ç¿ÁÒ½¨ÒéÏà¹ØµÄÓû§×èÖ¹µã»÷ÈκοÉÒɵÄÁ´½ÓÔì³ÉΣº¦£¬£¬£¬£¬ £¬£¬£¬£¬Çë¹Ø×¢¹Ù·½Ïà¹ØÐÂÎÅ£¬£¬£¬£¬ £¬£¬£¬£¬ÒÔ±ãʵʱÉý¼¶phpMyAdminÖÁÐÞ¸´°æÔ­À´·À»¤´ËÎó²î¡£¡£¡£


¡ñ²Î¿¼Á´½Ó


https://thehackernews.com/2019/09/phpmyadmin-csrf-exploit.html

https://seclists.org/fulldisclosure/2019/Sep/23