Arthur
07-30-2003, 10:04 AM
phpMyAdmin 2.5.2-pl1
Version 2.5.2-pl1 of phpMyAdmin (http://www.phpmyadmin.net), a third party database administration tool used by many of the FutureQuest Site Owners, has been released today. This new version repairs problems that include a bug that can be used to display a listing of the phpMyAdmin directory, and path discloser and XSS* problems. In addition the password is now encrypted using the blowfish algorithm.
Users are encouraged to upgrade to this new version.
The new version can be downloaded from http://sourceforge.net/project/showfiles.php?group_id=23067, or http://www.phpmyadmin.net.
Informational links:
http://www.phpmyadmin.net/documentation/#faqsecurity
http://www.securityfocus.com/archive/1/325641
* Cross Site Scripting
--
Arthur
Version 2.5.2-pl1 of phpMyAdmin (http://www.phpmyadmin.net), a third party database administration tool used by many of the FutureQuest Site Owners, has been released today. This new version repairs problems that include a bug that can be used to display a listing of the phpMyAdmin directory, and path discloser and XSS* problems. In addition the password is now encrypted using the blowfish algorithm.
Users are encouraged to upgrade to this new version.
The new version can be downloaded from http://sourceforge.net/project/showfiles.php?group_id=23067, or http://www.phpmyadmin.net.
Informational links:
http://www.phpmyadmin.net/documentation/#faqsecurity
http://www.securityfocus.com/archive/1/325641
* Cross Site Scripting
--
Arthur