PT-2005-1696 · Php · Phpmyadmin

Maksymilian Arciemowicz

·

Published

2005-03-07

·

Updated

2008-09-05

·

CVE-2005-0653

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions phpMyAdmin version 2.6.1
Description The issue concerns improper permission granting on tables with an underscore in the name, allowing remote authenticated users to have more privileges than intended.
Recommendations For phpMyAdmin version 2.6.1, update to a newer version that properly handles permissions for tables with underscores in their names to prevent unintended privilege escalation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0653

Affected Products

Phpmyadmin