phpMyAdmin¿çÕ¾ÇëÇóαÔìÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-09-23¡ñÎó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-12922£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º6.5
¡ñÓ°Ïì°æ±¾
phpMyAdmin<= 4.9.0.1
¡ñÎó²î¸ÅÊö
phpMyAdminÊÇÒ»¸öMySQLºÍMariaDBÊý¾Ý¿âµÄÃâ·Ñ¿ªÔ´ÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬£¬ÆÕ±éÓÃÓÚÖÎÀíWordPress¡¢JoomlaºÍÐí¶àÆäËûÄÚÈÝÖÎÀíÆ½Ì¨½¨ÉèµÄÍøÕ¾µÄÊý¾Ý¿â¡£¡£¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬£¬£¬£¬Çå¾²Ñо¿Ö°Ô±Manuel Garcia CardenasÅû¶ÁËphpMyAdminµÄÒ»¸ö¿çÕ¾ÇëÇóαÔ죨CVE-2019-12922£©Îó²î¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÓÕʹÈÏÖ¤Óû§Ö´ÐжñÒâ²Ù×÷¡£¡£¡£¡£¡£¡£µ±¹¥»÷Õß½«¶ñÒâ½á¹¹µÄURL·¢Ë͸øÄ¿µÄwebÖÎÀíԱʱ£¬£¬£¬£¬£¬£¬Èô¸ÃwebÖÎÀíÔ±ÒÑʹÓÃͳһä¯ÀÀÆ÷Éϰ¶ÁËphpmyAdminÃæ°å£¬£¬£¬£¬£¬£¬²¢·¿ª¸ÃÁ´½Ó£¬£¬£¬£¬£¬£¬¼´¿ÉÖ´ÐÐURL°üÀ¨µÄ¶ñÒâÇëÇóɾ³ýÄ¿µÄЧÀÍÆ÷ÉÏphpMyAdminÃæ°åÉèÖÃÒ³ÃæÖÐËùÉèÖõÄЧÀÍÆ÷¡£¡£¡£¡£¡£¡£
¡ñÎó²îÑéÖ¤
POC:ʹÓà CSRF ¡ªÉ¾³ýÖ÷ЧÀÍÆ÷¡£¡£¡£¡£¡£¡£
<p>Deleting Server 1</p>
<img src="
http://server/phpmyadmin/setup/index.php?page=servers&mode=remove&id=1";
style="display:none;" />
¡ñÐÞ¸´½¨Òé
¹Ù·½ÔÝδÐû²¼Õë¶Ô´ËÎó²îµÄÐÞ¸´°æ±¾¡£¡£¡£¡£¡£¡£
ÔÝʱ»º½â²½·¥£º
Óû§¿Éͨ¹ýÔÚÿ´ÎŲÓÃʱʹÓÃtoken±äÁ¿ÑéÖ¤À´¶Ô¸ÃÎó²î¾ÙÐзÀ»¤¡£¡£¡£¡£¡£¡£
ÔÚά»¤Ö°Ô±¶Ô¸ÃÎó²î¾ÙÐÐÐÞ¸´Ç°£¬£¬£¬£¬£¬£¬Ç¿ÁÒ½¨ÒéÏà¹ØµÄÓû§×èÖ¹µã»÷ÈκοÉÒɵÄÁ´½ÓÔì³ÉΣº¦£¬£¬£¬£¬£¬£¬Çë¹Ø×¢¹Ù·½Ïà¹ØÐÂÎÅ£¬£¬£¬£¬£¬£¬ÒÔ±ãʵʱÉý¼¶phpMyAdminÖÁÐÞ¸´°æÔÀ´·À»¤´ËÎó²î¡£¡£¡£¡£¡£¡£
¡ñ²Î¿¼Á´½Ó
https://thehackernews.com/2019/09/phpmyadmin-csrf-exploit.html
https://seclists.org/fulldisclosure/2019/Sep/23