10
CVSSv2

CVE-2004-1147

Published: 10/01/2005 Updated: 11/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

phpMyAdmin 2.6.0-pl2, and other versions prior to 2.6.1, with external transformations enabled, allows remote malicious users to execute arbitrary commands via shell metacharacters.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 2.4.0

phpmyadmin phpmyadmin 2.5.5_rc1

phpmyadmin phpmyadmin 2.5.5_rc2

phpmyadmin phpmyadmin 2.5.5

phpmyadmin phpmyadmin 2.5.5_pl1

phpmyadmin phpmyadmin 2.6.0_pl2

phpmyadmin phpmyadmin 2.6.0_pl3

phpmyadmin phpmyadmin 2.5.0

phpmyadmin phpmyadmin 2.5.1

phpmyadmin phpmyadmin 2.5.6_rc1

phpmyadmin phpmyadmin 2.5.7

phpmyadmin phpmyadmin 2.5.2

phpmyadmin phpmyadmin 2.5.4

phpmyadmin phpmyadmin 2.5.7_pl1

phpmyadmin phpmyadmin 2.6.0_pl1

Exploits

source: wwwsecurityfocuscom/bid/11886/info phpMyAdmin is reported prone to multiple remote vulnerabilities These issues can allow remote attackers to execute arbitrary commands and disclose files on a vulnerable computer These issues result from insufficient sanitization of user-supplied data The command execution is reported to be pr ...