Current time: 05-22-2024, 01:50 PM Hello There, Guest! (LoginRegister)


Post Reply 
PMA Security vulnerability ?
Author Message
joximu Offline
helper
*****
Moderators

Posts: 7,024
Joined: Jan 2007
Reputation: 92
Post: #2
RE: PMA Security vulnerability ?
VhCsOm3g4 - VHCSOMEGA in leet language...

Log in into pma and then have alook at the cookies in your browser.
So, it may be a security issue. If you give the cookie infos to me, I think I am maybe able to log in into your pma.... and since the cookie info is not secured by a https or something else it's maybe better to use a random string as secret.
And with your great update FAQ the secret stays the same since it's in the config.inc.php :-)

/Joximu
05-30-2007 07:47 PM
Visit this user's website Find all posts by this user Quote this message in a reply
Post Reply 


Messages In This Thread
PMA Security vulnerability ? - BeNe - 05-30-2007, 07:11 PM
RE: PMA Security vulnerability ? - joximu - 05-30-2007 07:47 PM
RE: PMA Security vulnerability ? - BeNe - 05-30-2007, 11:34 PM
RE: PMA Security vulnerability ? - RatS - 05-31-2007, 02:22 AM
RE: PMA Security vulnerability ? - BeNe - 05-31-2007, 02:40 AM
RE: PMA Security vulnerability ? - joximu - 05-31-2007, 03:23 AM
RE: PMA Security vulnerability ? - RatS - 05-31-2007, 07:30 AM
RE: PMA Security vulnerability ? - joximu - 05-31-2007, 08:33 AM
RE: PMA Security vulnerability ? - raphael - 05-31-2007, 10:17 AM
RE: PMA Security vulnerability ? - raphael - 05-31-2007, 11:22 AM
RE: PMA Security vulnerability ? - joximu - 05-31-2007, 05:07 PM
RE: PMA Security vulnerability ? - BeNe - 05-31-2007, 11:12 PM
RE: PMA Security vulnerability ? - raphael - 06-01-2007, 10:21 AM

Forum Jump:


User(s) browsing this thread: 1 Guest(s)