First published: Sun Feb 27 2005(Updated: )
Multiple PHP remote file inclusion vulnerabilities in phpMyAdmin 2.6.1 allow remote attackers to execute arbitrary PHP code by modifying the (1) theme parameter to phpmyadmin.css.php or (2) cfg[Server][extension] parameter to database_interface.lib.php to reference a URL on a remote web server that contains the code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyAdmin | =2.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0567 is considered a high severity vulnerability due to its potential for remote code execution.
To fix CVE-2005-0567, upgrade phpMyAdmin to a version newer than 2.6.1 where the vulnerability has been patched.
CVE-2005-0567 affects phpMyAdmin version 2.6.1.
Yes, CVE-2005-0567 can lead to data breaches as it allows attackers to execute arbitrary PHP code.
Attackers can exploit CVE-2005-0567 by manipulating the theme parameter and the database_interface.lib.php configuration file.