CVE-2004-2630: High severity phpMyAdmin phpMyAdmin vulnerability
Published Dec 31, 2004
·Updated
The MIME transformation system (transformations/textplainexternal.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.
Affected Software
15 affected components
phpMyAdmin phpMyAdmin=2.5.2_pl1
phpMyAdmin phpMyAdmin=2.5.0
phpMyAdmin phpMyAdmin=2.5.5_rc1
phpMyAdmin phpMyAdmin=2.5.7_pl1
phpMyAdmin phpMyAdmin=2.5.5
phpMyAdmin phpMyAdmin=2.5.7
phpMyAdmin phpMyAdmin=2.5.6_rc1
phpMyAdmin phpMyAdmin=2.6.0_pl1
phpMyAdmin phpMyAdmin=2.5.2
phpMyAdmin phpMyAdmin=2.5.1
phpMyAdmin phpMyAdmin=2.5.4
phpMyAdmin phpMyAdmin=2.5.3
phpMyAdmin phpMyAdmin=2.5.6_rc2
phpMyAdmin phpMyAdmin=2.5.5_rc2
phpMyAdmin phpMyAdmin=2.5.5_pl1
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Dec 5, 2005
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2630?
CVE-2004-2630 is considered a high severity vulnerability due to its ability to allow remote command execution.
2
How do I fix CVE-2004-2630?
To fix CVE-2004-2630, update phpMyAdmin to a version greater than 2.6.0-pl1.
3
Which versions of phpMyAdmin are affected by CVE-2004-2630?
CVE-2004-2630 affects phpMyAdmin versions 2.5.0 through 2.6.0-pl1.
4
Can CVE-2004-2630 be exploited remotely?
Yes, CVE-2004-2630 can be exploited remotely by an attacker using specially crafted input.
5
What actions can attackers take due to CVE-2004-2630?
Attackers can execute arbitrary commands on the server due to the vulnerability in CVE-2004-2630.