Lucene search

K
ubuntucveUbuntu.comUB:CVE-2005-3300
HistoryOct 23, 2005 - 12:00 a.m.

CVE-2005-3300

2005-10-2300:00:00
ubuntu.com
ubuntu.com
11

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS

0.023

Percentile

89.6%

The register_globals emulation layer in grab_globals.php for phpMyAdmin
before 2.6.4-pl3 does not perform safety checks on values in the _FILES
array for uploaded files, which allows remote attackers to include
arbitrary files by using direct requests to library scripts that do not use
grab_globals.php, then modifying certain configuration values for the
theme.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchphpmyadmin< 2.8.0.3-1UNKNOWN
ubuntu6.10noarchphpmyadmin< 2.8.0.3-1UNKNOWN
ubuntu7.04noarchphpmyadmin< 2.8.0.3-1UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS

0.023

Percentile

89.6%