CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:C/I:C/A:C
AI Score
Confidence
Low
EPSS
Percentile
88.1%
phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters.
Vendor | Product | Version | CPE |
---|---|---|---|
phpmyadmin | phpmyadmin | 2.4.0 | cpe:2.3:a:phpmyadmin:phpmyadmin:2.4.0:*:*:*:*:*:*:* |
phpmyadmin | phpmyadmin | 2.5.0 | cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.0:*:*:*:*:*:*:* |
phpmyadmin | phpmyadmin | 2.5.1 | cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.1:*:*:*:*:*:*:* |
phpmyadmin | phpmyadmin | 2.5.2 | cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.2:*:*:*:*:*:*:* |
phpmyadmin | phpmyadmin | 2.5.4 | cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.4:*:*:*:*:*:*:* |
phpmyadmin | phpmyadmin | 2.5.5 | cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.5:*:*:*:*:*:*:* |
phpmyadmin | phpmyadmin | 2.5.5_pl1 | cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.5_pl1:*:*:*:*:*:*:* |
phpmyadmin | phpmyadmin | 2.5.5_rc1 | cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.5_rc1:*:*:*:*:*:*:* |
phpmyadmin | phpmyadmin | 2.5.5_rc2 | cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.5_rc2:*:*:*:*:*:*:* |
phpmyadmin | phpmyadmin | 2.5.6_rc1 | cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.6_rc1:*:*:*:*:*:*:* |