7.5
CVSSv2

CVE-2004-2631

Published: 31/12/2004 Updated: 20/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote malicious users to execute arbitrary PHP code via a crafted table name.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 2.5.2 pl1

phpmyadmin phpmyadmin 2.5.5 rc1

phpmyadmin phpmyadmin 2.5.5

phpmyadmin phpmyadmin 2.5.7

phpmyadmin phpmyadmin 2.5.6 rc1

phpmyadmin phpmyadmin 2.5.2

phpmyadmin phpmyadmin 2.5.1

phpmyadmin phpmyadmin 2.5.4

phpmyadmin phpmyadmin 2.5.3

phpmyadmin phpmyadmin 2.5.6 rc2

phpmyadmin phpmyadmin 2.5.5 rc2

phpmyadmin phpmyadmin 2.5.5 pl1

Exploits

/* * phpmy-expltc * written by Nasir Simbolon <nasir kecapi com> * eagle kecapi com * Jakarta, Indonesia * * June, 10 2004 * * A phpMyAdmin-257 exploite program * This is a kind of mysql server wrapper acts like a proxy except that it will sends a fake table name, * when client query "SHOW TABLES", by replacing the ...