10
CVSSv2

CVE-2004-1147

Published: 10/01/2005 Updated: 11/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

phpMyAdmin 2.6.0-pl2, and other versions prior to 2.6.1, with external transformations enabled, allows remote malicious users to execute arbitrary commands via shell metacharacters.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 2.5.0

phpmyadmin phpmyadmin 2.5.5 rc1

phpmyadmin phpmyadmin 2.6.0 pl3

phpmyadmin phpmyadmin 2.5.7 pl1

phpmyadmin phpmyadmin 2.4.0

phpmyadmin phpmyadmin 2.5.5

phpmyadmin phpmyadmin 2.5.7

phpmyadmin phpmyadmin 2.5.6 rc1

phpmyadmin phpmyadmin 2.6.0 pl1

phpmyadmin phpmyadmin 2.5.2

phpmyadmin phpmyadmin 2.5.1

phpmyadmin phpmyadmin 2.6.0 pl2

phpmyadmin phpmyadmin 2.5.4

phpmyadmin phpmyadmin 2.5.5 rc2

phpmyadmin phpmyadmin 2.5.5 pl1

Exploits

source: wwwsecurityfocuscom/bid/11886/info phpMyAdmin is reported prone to multiple remote vulnerabilities These issues can allow remote attackers to execute arbitrary commands and disclose files on a vulnerable computer These issues result from insufficient sanitization of user-supplied data The command execution is reported to be pr ...