PT-2005-4811 · Phpmyadmin · Phpmyadmin
Stefan Esser
·
Published
2005-12-08
·
Updated
2018-10-19
·
CVE-2005-4079
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
phpMyAdmin version 2.7.0 rc1
Description
The issue in phpMyAdmin allows remote attackers to exploit other weaknesses by modifying the
import blacklist variable in grab globals.php. This can then be used to overwrite other variables, potentially leading to further exploitation.Recommendations
For phpMyAdmin version 2.7.0 rc1, consider restricting access to the grab globals.php file or modifying the
import blacklist variable to prevent unauthorized changes until a patch is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpmyadmin