Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown
CVE-2004-1055
Disclosure Date: March 01, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PmaAbsoluteUri parameter, (2) the zero_rows parameter in read_dump.php, (3) the confirm form, or (4) an error message generated by the internal phpMyAdmin parser.
0
Attacker Value
Unknown
CVE-2004-1148
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter.
0
Attacker Value
Unknown
CVE-2004-1147
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters.
0
Attacker Value
Unknown
CVE-2004-2630
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The MIME transformation system (transformations/text_plain__external.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.
0
Attacker Value
Unknown
CVE-2004-0129
Disclosure Date: March 03, 2004 (last updated February 22, 2025)
Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in the what parameter.
0