Description
Multiple PHP remote file inclusion vulnerabilities in phpMyAdmin 2.6.1 allow remote attackers to execute arbitrary PHP code by modifying the (1) theme parameter to phpmyadmin.css.php or (2) cfg[Server][extension] parameter to database_interface.lib.php to reference a URL on a remote web server that contains the code.
Remediation
References
Related Vulnerabilities
Moodle Insertion of Sensitive Information into Log File Vulnerability (CVE-2012-1156)
WordPress Plugin Twitter Feed Cross-Site Scripting (2.0.4)
WordPress Other Vulnerability (CVE-2004-1559)
WordPress Plugin Product Catalog 8 SQL Injection (1.2.0)
WordPress Plugin External Links-nofollow, noopener & new window Cross-Site Scripting (2.55)