CVE-2005-3299
phpMyAdmin 2.6.4 and 2.6.4-pl1 - Remote File Inclusion via $__redirect Parameter
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2005-3299. PoCs published by cXIb8O3, RizeKishimaro, Cr0w-ui.
AI-analyzed exploit summary This exploit leverages a local file inclusion vulnerability in phpMyAdmin 2.6.4-pl1 by sending a crafted POST request to include arbitrary files via the `grab_globals.lib.php` script. The exploit reads the response to confirm file existence or display its contents.
Description
PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array.
Exploits (3)
This exploit leverages a local file inclusion vulnerability in phpMyAdmin 2.6.4-pl1 by sending a crafted POST request to include arbitrary files via the `grab_globals.lib.php` script. The exploit reads the response to confirm file existence or display its contents.
This Perl script exploits a file inclusion vulnerability in phpMyAdmin 2.6.4-pl1 by sending a crafted POST request to include arbitrary files (e.g., /etc/passwd). It demonstrates the vulnerability by leveraging improper input validation in the `grab_globals.lib.php` script.