CVE-2004-2631

phpMyAdmin <2.5.8 - Command Injection

Title source: llm

Description

Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary PHP code via a crafted table name.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Nasir Simbolon · cwebappsphp
https://www.exploit-db.com/exploits/309

Scores

EPSS 0.1420
EPSS Percentile 94.4%

Details

Status published
Products (12)
phpmyadmin/phpmyadmin 2.5.1
phpmyadmin/phpmyadmin 2.5.2
phpmyadmin/phpmyadmin 2.5.2_pl1
phpmyadmin/phpmyadmin 2.5.3
phpmyadmin/phpmyadmin 2.5.4
phpmyadmin/phpmyadmin 2.5.5
phpmyadmin/phpmyadmin 2.5.5_pl1
phpmyadmin/phpmyadmin 2.5.5_rc1
phpmyadmin/phpmyadmin 2.5.5_rc2
phpmyadmin/phpmyadmin 2.5.6_rc1
... and 2 more
Published Dec 31, 2004
Tracked Since Feb 18, 2026