当前位置:网站首页>Pagoda phpMyAdmin unauthorized access vulnerability
Pagoda phpMyAdmin unauthorized access vulnerability
2022-07-28 23:43:00 【Chu Bing】
pagoda phpmyadmin Unauthorized access vulnerability
This article is only for study , It is strictly forbidden to use it for illegal purposes , Otherwise, we will be responsible for the consequences .
Vulnerability profile
【 Pagoda panel 】 Emergency security update notification ,Linux panel 7.4.2 edition /Windows panel 6.8 There are security risks in version , There is no such risk in other versions . An urgent update has been released , All users using this version must upgrade to the latest version , Update method , Login panel can be upgraded directly , If there is a problem with the update , Please log in to pagoda forum for feedback or contact customer service for feedback
Holes affect
Linux Official version 7.4.2
Linux The beta 7.5.13
Windows Official version 6.8
Installed phpmyadmin,mysql database .( Other versions do not affect )
to open up 888 And it's not configured http authentication
FOFA grammar
app=" pagoda -Linux Control panel "
Loophole recurrence
Usually installed on the pagoda panel phpmyadmin Database management software , As long as the corresponding method , You can operate the database without user name and password
among 888 Is the default port , If custom port , It may be other ports , You can test whether there is this vulnerability
visit http://xxx.xxx.xxx.xxx:888/pma that will do

Bug repair
Upgraded version , Or use a safe version
By modifying the pma The configuration file , Mask the corresponding port , Closing public access rights and other methods can also solve
边栏推荐
- 解决线程安全问题&&单例模式
- 欲要让数字零售继续发挥作用,我们需要对数字零售赋予新的内涵和意义
- 【数据挖掘工程师-笔试】2022年大华股份
- My second uncle is angry and swipes the screen all over the network. How can he cure my spiritual internal friction?
- wget什么意思
- How to open a profitable gym? I tell you from one year's experience that don't fall in love
- Manufacturing steps of interactive slide screen in exhibition hall
- 通过Wi-Fi 7实现极高吞吐量——洞察下一代Wi-Fi物理层
- 集火全屋智能“后装市场”,真正玩得转的没几个
- 2022 simulated examination platform operation of hoisting machinery command examination questions
猜你喜欢

字节8年女测试总监工作感悟—写给想转行或即将进入测试行业的女生们...

22 Niuke multi school Day1 I - Introduction to chiitoitsu DP

苹果官网正在更新维护 Apple Store,国行 iPhone 13 / Pro 等产品将最高优惠 600 元

类中多函数填写,LeetCode919——完全二叉树插入器

2022t elevator repair examination questions and simulation examination

22牛客多校day1 I - Chiitoitsu 概论dp

1314_串口技术_RS232通信基础的信息

MyCms 自媒体商城 v3.6 发布,兼容微擎应用开发(Laravel框架)

Why did "you" become a test / development programmer? The value of your existence
![[self] - brush questions set](/img/de/46582086addbe5465d658081516f4c.png)
[self] - brush questions set
随机推荐
[self] - question brushing - peak value
2022t elevator repair examination questions and simulation examination
Byte 8 years' experience of female test Director - for girls who want to change careers or are about to enter the testing industry
Fundamental inquiry binary tree
XML modeling
「行泊一体」放量,福瑞泰克高性能域控制器领跑新赛道
Rhce第二天
【自】-刷题-峰值
被忽视的智能电视小程序领域
How to open a profitable gym? I tell you from one year's experience that don't fall in love
英特尔数据中心GPU正式发货,以开放灵活提供强劲算力
2022T电梯修理考试试题及模拟考试
Read the recent trends of okaleido tiger and tap the value and potential behind it
Compatibility description between kingbasees and Oracle (3. Common functions)
通过Wi-Fi 7实现极高吞吐量——洞察下一代Wi-Fi物理层
Class, leetcode919 -- complete binary tree inserter
JSP tag case
【CNN】为什么CNN的卷积核大小一般都是奇数
The front mounted ADAS camera in parking increased by 54.15% year-on-year, with TOP10 suppliers taking the lead
超参数优化(网格搜索和贝叶斯优化)