CVE-2004-2631

phpMyAdmin <2.5.8 - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-2631. PoCs published by Nasir Simbolon.

AI-analyzed exploit summary This exploit acts as a proxy between a client and a MySQL server, intercepting and manipulating the response to a 'SHOW TABLES' query to inject arbitrary PHP code into phpMyAdmin. The injected code executes a command to create a file, demonstrating remote code execution (RCE).

Description

Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary PHP code via a crafted table name.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Nasir Simbolon · cwebappsphp
https://www.exploit-db.com/exploits/309

This exploit acts as a proxy between a client and a MySQL server, intercepting and manipulating the response to a 'SHOW TABLES' query to inject arbitrary PHP code into phpMyAdmin. The injected code executes a command to create a file, demonstrating remote code execution (RCE).

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: phpMyAdmin 2.5.7
Auth required
Prerequisites: Access to a vulnerable phpMyAdmin instance · Ability to configure a malicious server to intercept MySQL traffic · Valid credentials for the target phpMyAdmin instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (12)

Core 12
Core References
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2004-06/0473.html
Patch vdb-entry x_refsource_osvdb
http://www.osvdb.org/7314
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11974
Exploit mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2004-06/0444.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16542
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=109816584519779&w=2
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10629
Exploit vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1010614
Third Party Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200407-22.xml

Scores

EPSS 0.0935
EPSS Percentile 94.7%

Details

Status published
Products (12)
phpmyadmin/phpmyadmin 2.5.1
phpmyadmin/phpmyadmin 2.5.2
phpmyadmin/phpmyadmin 2.5.2_pl1
phpmyadmin/phpmyadmin 2.5.3
phpmyadmin/phpmyadmin 2.5.4
phpmyadmin/phpmyadmin 2.5.5
phpmyadmin/phpmyadmin 2.5.5_pl1
phpmyadmin/phpmyadmin 2.5.5_rc1
phpmyadmin/phpmyadmin 2.5.5_rc2
phpmyadmin/phpmyadmin 2.5.6_rc1
... and 2 more
Published Dec 31, 2004
Tracked Since Feb 18, 2026