First published: Sun Oct 23 2005(Updated: )
PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PhpMyAdmin | =2.6.4_pl1 | |
PhpMyAdmin | =2.6.4 | |
phpMyAdmin | =2.6.4 | |
phpMyAdmin | =2.6.4_pl1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3299 is considered a high severity vulnerability due to its potential for remote code execution through file inclusion.
To fix CVE-2005-3299, upgrade phpMyAdmin to version 2.6.4-pl2 or later.
CVE-2005-3299 affects phpMyAdmin versions 2.6.4 and 2.6.4-pl1.
CVE-2005-3299 is a PHP file inclusion vulnerability.
CVE-2005-3299 can be exploited by remote attackers who can manipulate the $__redirect parameter.