Description
phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration settings and gain unauthorized access to MySQL servers via modified $cfg['Servers'] variables.
References (10)
Core 10
Core References
Third Party Advisory mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2004-06/0473.html
Patch x_refsource_confirm
http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2004-1
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/11974
Exploit mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2004-06/0444.html
Patch vdb-entry
x_refsource_osvdb
http://www.osvdb.org/7315
Exploit, Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/10629
Exploit vdb-entry
x_refsource_sectrack
http://securitytracker.com/alerts/2004/Jun/1010614.html
Patch vendor-advisory
x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200407-22.xml
Exploit x_refsource_misc
http://eagle.kecapi.com/sec/fd/phpMyAdmin.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16555
Scores
EPSS
0.0295
EPSS Percentile
86.6%
Details
Status
published
Products (12)
phpmyadmin/phpmyadmin
2.5.1
phpmyadmin/phpmyadmin
2.5.2
phpmyadmin/phpmyadmin
2.5.2_pl1
phpmyadmin/phpmyadmin
2.5.3
phpmyadmin/phpmyadmin
2.5.4
phpmyadmin/phpmyadmin
2.5.5
phpmyadmin/phpmyadmin
2.5.5_pl1
phpmyadmin/phpmyadmin
2.5.5_rc1
phpmyadmin/phpmyadmin
2.5.5_rc2
phpmyadmin/phpmyadmin
2.5.6_rc1
... and 2 more
Published
Dec 31, 2004
Tracked Since
Feb 18, 2026