PT-2004-2040 · Php · Phpmyadmin
Cedric Cochin
·
Publicado
2004-11-24
·
Atualizado
2017-07-11
·
CVE-2004-1055
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
phpMyAdmin versions 2.6.0-pl2 and earlier
Description:
The issue allows remote attackers to inject arbitrary web script or HTML via several parameters and components, including the
PmaAbsoluteUri parameter, the zero rows parameter in read dump.php, the confirm form, or an error message generated by the internal phpMyAdmin parser.Recommendations:
For phpMyAdmin versions 2.6.0-pl2 and earlier, update to a version later than 2.6.0-pl2 to resolve the issue.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Phpmyadmin