CVE-2004-1147: Critical severity phpmyadmin phpmyadmin vulnerability
Published Dec 15, 2004
·Updated
phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters.
Affected Software
15 affected components
phpMyAdmin phpMyAdmin=2.5.0
phpMyAdmin phpMyAdmin=2.5.5_rc1
phpMyAdmin phpMyAdmin=2.6.0_pl3
phpMyAdmin phpMyAdmin=2.5.7_pl1
phpMyAdmin phpMyAdmin=2.4.0
phpMyAdmin phpMyAdmin=2.5.5
phpMyAdmin phpMyAdmin=2.5.7
phpMyAdmin phpMyAdmin=2.5.6_rc1
phpMyAdmin phpMyAdmin=2.6.0_pl1
phpMyAdmin phpMyAdmin=2.5.2
phpMyAdmin phpMyAdmin=2.5.1
phpMyAdmin phpMyAdmin=2.6.0_pl2
phpMyAdmin phpMyAdmin=2.5.4
phpMyAdmin phpMyAdmin=2.5.5_rc2
phpMyAdmin phpMyAdmin=2.5.5_pl1
Event History
Dec 15, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1147?
CVE-2004-1147 is considered to have a high severity due to its potential for remote command execution.
2
How do I fix CVE-2004-1147?
To fix CVE-2004-1147, upgrade to phpMyAdmin version 2.6.1 or later where the vulnerability has been addressed.
3
What versions of phpMyAdmin are affected by CVE-2004-1147?
CVE-2004-1147 affects phpMyAdmin versions 2.6.0-pl2 and earlier, including versions 2.5.x.
4
What type of vulnerability is CVE-2004-1147?
CVE-2004-1147 is a remote command execution vulnerability due to improper handling of shell metacharacters.
5
Can CVE-2004-1147 be exploited without authentication?
Yes, CVE-2004-1147 can be exploited by remote attackers without the need for authentication.