Total vulnerabilities in the database
phpMyAdmin 2.2.0rc3 and earlier allows remote attackers to execute arbitrary commands by inserting them into (1) the strCopyTableOK argument in tbl_copy.php, or (2) the strRenameTableOK argument in tbl_rename.php.
Software | From | Fixed in |
---|---|---|
phpmyadmin / phpmyadmin | 2.1.1 | 2.1.1.x |
phpmyadmin / phpmyadmin | 2.1.2 | 2.1.2.x |
phpmyadmin / phpmyadmin | 2.2_pre1 | 2.2_pre1.x |
phpmyadmin / phpmyadmin | 2.0.4 | 2.0.4.x |
phpmyadmin / phpmyadmin | 2.0.2 | 2.0.2.x |
phpmyadmin / phpmyadmin | 2.0.3 | 2.0.3.x |
phpmyadmin / phpmyadmin | 2.1 | 2.1.x |
phpmyadmin / phpmyadmin | 2.0.1 | 2.0.1.x |
phpmyadmin / phpmyadmin | 2.2_rc2 | 2.2_rc2.x |
phpmyadmin / phpmyadmin | 2.2_rc3 | 2.2_rc3.x |
phpmyadmin / phpmyadmin | 2.2_rc1 | 2.2_rc1.x |
phpmyadmin / phpmyadmin | 2.0 | 2.0.x |
phpmyadmin / phpmyadmin | 2.0.5 | 2.0.5.x |