PHPMyAdmin Server_databases Remote Code Execution Exploit

This module exploits a vulnerability in PHPMyAdmin. server_databases.php fails when it attemps to sanitize the sort_by parameter. It allows an attacker to inject code, and execute it on the web server with www-data privileges.
Tuesday, February 24, 2009 - 18:00