First published: Fri Dec 31 2004(Updated: )
phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration settings and gain unauthorized access to MySQL servers via modified $cfg['Servers'] variables.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PhpMyAdmin | =2.5.1 | |
PhpMyAdmin | =2.5.2 | |
PhpMyAdmin | =2.5.2_pl1 | |
PhpMyAdmin | =2.5.3 | |
PhpMyAdmin | =2.5.4 | |
PhpMyAdmin | =2.5.5 | |
PhpMyAdmin | =2.5.5_pl1 | |
PhpMyAdmin | =2.5.5_rc1 | |
PhpMyAdmin | =2.5.5_rc2 | |
PhpMyAdmin | =2.5.6_rc1 | |
PhpMyAdmin | =2.5.6_rc2 | |
PhpMyAdmin | =2.5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2632 has been classified as having a medium severity level.
To fix CVE-2004-2632, upgrade your phpMyAdmin installation to version 2.5.8 or later.
CVE-2004-2632 affects phpMyAdmin versions from 2.5.1 to 2.5.7.
CVE-2004-2632 allows remote attackers to modify configuration settings and gain unauthorized access to MySQL servers.
Authentication is not required to exploit CVE-2004-2632, making it particularly dangerous.