Vulnerabilities > CVE-2004-2632 - Unspecified vulnerability in PHPmyadmin
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN phpmyadmin
nessus
Summary
phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration settings and gain unauthorized access to MySQL servers via modified $cfg['Servers'] variables.
Vulnerable Configurations
Nessus
NASL family | Gentoo Local Security Checks |
NASL id | GENTOO_GLSA-200407-22.NASL |
description | The remote host is affected by the vulnerability described in GLSA-200407-22 (phpMyAdmin: Multiple vulnerabilities) Two serious vulnerabilities exist in phpMyAdmin. The first allows any user to alter the server configuration variables (including host, name, and password) by appending new settings to the array variables that hold the configuration in a GET statement. The second allows users to include arbitrary PHP code to be executed within an eval() statement in table name configuration settings. This second vulnerability is only exploitable if $cfg[ |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 14555 |
published | 2004-08-30 |
reporter | This script is Copyright (C) 2004-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/14555 |
title | GLSA-200407-22 : phpMyAdmin: Multiple vulnerabilities |
code |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2004-06/0444.html
- http://archives.neohapsis.com/archives/bugtraq/2004-06/0444.html
- http://archives.neohapsis.com/archives/bugtraq/2004-06/0473.html
- http://archives.neohapsis.com/archives/bugtraq/2004-06/0473.html
- http://eagle.kecapi.com/sec/fd/phpMyAdmin.html
- http://eagle.kecapi.com/sec/fd/phpMyAdmin.html
- http://secunia.com/advisories/11974
- http://secunia.com/advisories/11974
- http://securitytracker.com/alerts/2004/Jun/1010614.html
- http://securitytracker.com/alerts/2004/Jun/1010614.html
- http://www.gentoo.org/security/en/glsa/glsa-200407-22.xml
- http://www.gentoo.org/security/en/glsa/glsa-200407-22.xml
- http://www.osvdb.org/7315
- http://www.osvdb.org/7315
- http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2004-1
- http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2004-1
- http://www.securityfocus.com/bid/10629
- http://www.securityfocus.com/bid/10629
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16555
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16555