phpMyAdmin 2.2.0rc3 and earlier allows remote attackers to execute arbitrary commands by inserting them into (1) the strCopyTableOK argument in tbl_copy.php, or (2) the strRenameTableOK argument in tbl_rename.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpmyadmin | Phpmyadmin | 2.0 (including) | 2.0 (including) |
Phpmyadmin | Phpmyadmin | 2.0.1 (including) | 2.0.1 (including) |
Phpmyadmin | Phpmyadmin | 2.0.2 (including) | 2.0.2 (including) |
Phpmyadmin | Phpmyadmin | 2.0.3 (including) | 2.0.3 (including) |
Phpmyadmin | Phpmyadmin | 2.0.4 (including) | 2.0.4 (including) |
Phpmyadmin | Phpmyadmin | 2.0.5 (including) | 2.0.5 (including) |
Phpmyadmin | Phpmyadmin | 2.1 (including) | 2.1 (including) |
Phpmyadmin | Phpmyadmin | 2.1.1 (including) | 2.1.1 (including) |
Phpmyadmin | Phpmyadmin | 2.1.2 (including) | 2.1.2 (including) |
Phpmyadmin | Phpmyadmin | 2.2_pre1 (including) | 2.2_pre1 (including) |
Phpmyadmin | Phpmyadmin | 2.2_rc1 (including) | 2.2_rc1 (including) |
Phpmyadmin | Phpmyadmin | 2.2_rc2 (including) | 2.2_rc2 (including) |
Phpmyadmin | Phpmyadmin | 2.2_rc3 (including) | 2.2_rc3 (including) |