Description
GUnet OpenEclass 1.7.3 includes phpMyAdmin 2.10.0.2 by default, which allows remote logins. Attackers with access to the platform can remotely access phpMyAdmin and, after uploading a shell, view the config.php file to obtain the MySQL password, leading to full database compromise.
Problem types
Improper Access Control (phpMyAdmin Remote Access)
Product status
Credits
emaragkos
References
www.exploit-db.com/exploits/48163 (ExploitDB-48163)
www.openeclass.org/ (Official Vendor Homepage)
download.openeclass.org/files/docs/1.7/CHANGES.txt (Changelog)
www.vulncheck.com/...rning-platform-phpmyadmin-remote-access (VulnCheck Advisory: GUnet OpenEclass 1.7.3 E-learning platform - phpMyAdmin Remote Access)