Vulnerabilities > CVE-2004-2631 - Unspecified vulnerability in PHPmyadmin
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary PHP code via a crafted table name.
Vulnerable Configurations
Exploit-Db
description | phpMyAdmin 2.5.7 Remote code injection Exploit. CVE-2004-2631. Webapps exploit for php platform |
id | EDB-ID:309 |
last seen | 2016-01-31 |
modified | 2004-07-04 |
published | 2004-07-04 |
reporter | Nasir Simbolon |
source | https://www.exploit-db.com/download/309/ |
title | phpMyAdmin 2.5.7 - Remote code Injection Exploit |
Nessus
NASL family | Gentoo Local Security Checks |
NASL id | GENTOO_GLSA-200407-22.NASL |
description | The remote host is affected by the vulnerability described in GLSA-200407-22 (phpMyAdmin: Multiple vulnerabilities) Two serious vulnerabilities exist in phpMyAdmin. The first allows any user to alter the server configuration variables (including host, name, and password) by appending new settings to the array variables that hold the configuration in a GET statement. The second allows users to include arbitrary PHP code to be executed within an eval() statement in table name configuration settings. This second vulnerability is only exploitable if $cfg[ |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 14555 |
published | 2004-08-30 |
reporter | This script is Copyright (C) 2004-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/14555 |
title | GLSA-200407-22 : phpMyAdmin: Multiple vulnerabilities |
code |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2004-06/0444.html
- http://archives.neohapsis.com/archives/bugtraq/2004-06/0473.html
- http://eagle.kecapi.com/sec/fd/phpMyAdmin.html
- http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2004-1
- http://www.gentoo.org/security/en/glsa/glsa-200407-22.xml
- http://www.securiteam.com/unixfocus/5QP040ADFW.html
- http://www.securityfocus.com/bid/10629
- http://www.osvdb.org/7314
- http://securitytracker.com/id?1010614
- http://secunia.com/advisories/11974
- http://marc.info/?l=bugtraq&m=109816584519779&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16542