Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown

CVE-2004-1055

Disclosure Date: March 01, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PmaAbsoluteUri parameter, (2) the zero_rows parameter in read_dump.php, (3) the confirm form, or (4) an error message generated by the internal phpMyAdmin parser.
0
Attacker Value
Unknown

CVE-2004-1148

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter.
0
Attacker Value
Unknown

CVE-2004-1147

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters.
0
Attacker Value
Unknown

CVE-2004-2630

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The MIME transformation system (transformations/text_plain__external.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.
0
Attacker Value
Unknown

CVE-2004-0129

Disclosure Date: March 03, 2004 (last updated February 22, 2025)
Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in the what parameter.
0