Vulnerability Name: | CVE-2004-2631 (CCN-16542) | ||||||||
Assigned: | 2004-06-28 | ||||||||
Published: | 2004-06-28 | ||||||||
Updated: | 2017-07-20 | ||||||||
Summary: | Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary PHP code via a crafted table name. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: BUGTRAQ Type: Exploit 20040628 php codes injection in phpMyAdmin version 2.5.7. Source: CCN Type: BugTraq Mailing List, Mon Jun 28 2004 - 21:57:52 CDT php codes injection in phpMyAdmin version 2.5.7. Source: BUGTRAQ Type: UNKNOWN 20040630 Re: php codes injection in phpMyAdmin version 2.5.7. Source: CCN Type: BugTraq Mailing List, Thu Jul 01 2004 - 11:29:50 CDT Re: php codes injection in phpMyAdmin version 2.5.7. Source: MITRE Type: CNA CVE-2004-2631 Source: MISC Type: Exploit http://eagle.kecapi.com/sec/fd/phpMyAdmin.html Source: BUGTRAQ Type: UNKNOWN 20041018 phpMyAdmin: Vulnerability in MIME-based transformation Source: CCN Type: SA11974 phpMyAdmin Configuration Manipulation and Code Injection Source: SECUNIA Type: Patch, Vendor Advisory 11974 Source: CCN Type: SECTRACK ID: 1010614 phpMyAdmin Input Validation Errors in `left.php` May Let Remote Users Execute Arbitrary PHP Code Source: SECTRACK Type: Exploit 1010614 Source: CCN Type: GLSA-200407-22 phpMyAdmin: Multiple vulnerabilities Source: GENTOO Type: UNKNOWN GLSA-200407-22 Source: OSVDB Type: Patch 7314 Source: CCN Type: OSVDB ID: 7314 phpMyAdmin left.php Code Injection Source: CCN Type: phpMyAdmin Web site phpMyAdmin - Mysql DB administration tool Source: CONFIRM Type: Patch http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2004-1 Source: MISC Type: Exploit http://www.securiteam.com/unixfocus/5QP040ADFW.html Source: BID Type: Exploit, Patch 10629 Source: CCN Type: BID-10629 phpMyAdmin Multiple Input Validation Vulnerabilities Source: XF Type: UNKNOWN phpmyadmin-php-injection(16542) Source: XF Type: UNKNOWN phpmyadmin-php-injection(16542) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |