First published: Thu Dec 08 2005(Updated: )
The register_globals emulation in phpMyAdmin 2.7.0 rc1 allows remote attackers to exploit other vulnerabilities in phpMyAdmin by modifying the import_blacklist variable in grab_globals.php, which can then be used to overwrite other variables.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PhpMyAdmin | =2.7.0_rc1 | |
phpMyAdmin | =2.7.0_rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4079 is considered a moderate vulnerability that allows remote attackers to exploit other vulnerabilities in phpMyAdmin.
To fix CVE-2005-4079, upgrade phpMyAdmin to a version that does not use register_globals emulation.
CVE-2005-4079 specifically affects phpMyAdmin version 2.7.0 rc1.
Attackers can exploit CVE-2005-4079 to modify the import_blacklist variable, potentially leading to variable overwrites.
While CVE-2005-4079 has been documented for years, using outdated software like phpMyAdmin 2.7.0 rc1 poses a continuing security risk.