phpMyAdmin Arbitrary Command Execution Vulnerability
BID:3121
Info
phpMyAdmin Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 3121 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-1060 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 31 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | Reported to Bugtraq by Carl Livitt <[email protected]> on July 31, 2001. |
| Vulnerable: |
phpMyAdmin phpMyAdmin 2.2 rc3 phpMyAdmin phpMyAdmin 2.2 rc2 phpMyAdmin phpMyAdmin 2.2 rc1 phpMyAdmin phpMyAdmin 2.2 pre1 phpMyAdmin phpMyAdmin 2.1 .2 phpMyAdmin phpMyAdmin 2.1 .1 phpMyAdmin phpMyAdmin 2.1 phpMyAdmin phpMyAdmin 2.0.5 phpMyAdmin phpMyAdmin 2.0.4 phpMyAdmin phpMyAdmin 2.0.3 phpMyAdmin phpMyAdmin 2.0.2 phpMyAdmin phpMyAdmin 2.0.1 phpMyAdmin phpMyAdmin 2.0 |
| Not Vulnerable: |
phpMyAdmin phpMyAdmin 2.2.2 |
Discussion
phpMyAdmin Arbitrary Command Execution Vulnerability
phpMyAdmin is a freely available tool that provides a WWW interface for handling MySQL adminstrative tasks.
An input validation error exists in phpMyAdmin that could allow remote users to cause arbitrary commands to be executed by the PHP interpreter at runtime. This may result in the disclosure of sensitive information or the execution of arbitrary code on a host running the software.
No authentication mechanisms are enabled with default installations of phpMyAdmin.
phpMyAdmin is a freely available tool that provides a WWW interface for handling MySQL adminstrative tasks.
An input validation error exists in phpMyAdmin that could allow remote users to cause arbitrary commands to be executed by the PHP interpreter at runtime. This may result in the disclosure of sensitive information or the execution of arbitrary code on a host running the software.
No authentication mechanisms are enabled with default installations of phpMyAdmin.
References
phpMyAdmin Arbitrary Command Execution Vulnerability
References:
References: