CVE-2004-2631
phpMyAdmin <2.5.8 - Command Injection
Title source: llmDescription
Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary PHP code via a crafted table name.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Nasir Simbolon · cwebappsphp
https://www.exploit-db.com/exploits/309
References (12)
Scores
EPSS
0.1420
EPSS Percentile
94.4%
Details
Status
published
Products (12)
phpmyadmin/phpmyadmin
2.5.1
phpmyadmin/phpmyadmin
2.5.2
phpmyadmin/phpmyadmin
2.5.2_pl1
phpmyadmin/phpmyadmin
2.5.3
phpmyadmin/phpmyadmin
2.5.4
phpmyadmin/phpmyadmin
2.5.5
phpmyadmin/phpmyadmin
2.5.5_pl1
phpmyadmin/phpmyadmin
2.5.5_rc1
phpmyadmin/phpmyadmin
2.5.5_rc2
phpmyadmin/phpmyadmin
2.5.6_rc1
... and 2 more
Published
Dec 31, 2004
Tracked Since
Feb 18, 2026