Summary
The remote web server contains a PHP application that may allow arbitrary command execution.
Description :
According to its banner, the remote version of phpMyAdmin is vulnerable to an unspecified vulnerability in the MIME-based transformation system with 'external' transformations that may allow arbitrary command execution. Successful exploitation requires that PHP's 'safe_mode' be enabled.
Solution
Upgrade to phpMyAdmin version 2.6.0-pl2 or later.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2004-2630 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities