Vulnerability Description
The MIME transformation system (transformations/text_plain__external.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpmyadmin | Phpmyadmin | 2.5.0 |
References
- http://marc.info/?l=bugtraq&m=109816584519779&w=2
- http://marc.info/?l=full-disclosure&m=109810251501643&w=2
- http://secunia.com/advisories/12813Patch
- http://secunia.com/advisories/12859PatchVendor Advisory
- http://securitytracker.com/alerts/2004/Oct/1011761.htmlPatch
- http://www.gentoo.org/security/en/glsa/glsa-200410-14.xmlPatch
- http://www.osvdb.org/10715
- http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2004-2Patch
- http://www.securityfocus.com/bid/11391Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17698
- http://marc.info/?l=bugtraq&m=109816584519779&w=2
- http://marc.info/?l=full-disclosure&m=109810251501643&w=2
- http://secunia.com/advisories/12813Patch
- http://secunia.com/advisories/12859PatchVendor Advisory
- http://securitytracker.com/alerts/2004/Oct/1011761.htmlPatch
FAQ
What is CVE-2004-2630?
CVE-2004-2630 is a vulnerability with a CVSS score of 7.5 (HIGH). The MIME transformation system (transformations/text_plain__external.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows remote attackers to execute arbitrary commands via shell metacharacters in unsp...
How severe is CVE-2004-2630?
CVE-2004-2630 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-2630?
Check the references section above for vendor advisories and patch information. Affected products include: Phpmyadmin Phpmyadmin.