CVE-2004-2630
published 2004-12-31CVE-2004-2630: The MIME transformation system (transformations/text_plain__external.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows remote attackers to execute arbitrary…
PriorityP341high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.93%
85.5th percentile
The MIME transformation system (transformations/text_plain__external.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | phpmyadmin | < phpmyadmin 2:2.6.0-pl2-1 (bookworm) | phpmyadmin 2:2.6.0-pl2-1 (bookworm) |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | >= 0 < 2:2.6.0-pl2-1 | 2:2.6.0-pl2-1 |
| phpmyadmin | phpmyadmin | >= 0 < 2:2.6.0-pl2-1 | 2:2.6.0-pl2-1 |
| phpmyadmin | phpmyadmin | >= 0 < 2:2.6.0-pl2-1 | 2:2.6.0-pl2-1 |
| phpmyadmin | phpmyadmin | >= 0 < 2:2.6.0-pl2-1 | 2:2.6.0-pl2-1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gqxw-w7hq-j9fr: The MIME transformation system (transformations/text_plain__external
ghsa_unreviewed·2022-04-29
CVE-2004-2630 [HIGH] GHSA-gqxw-w7hq-j9fr: The MIME transformation system (transformations/text_plain__external
The MIME transformation system (transformations/text_plain__external.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.
OSV
CVE-2004-2630: The MIME transformation system (transformations/text_plain__external
osv·2004-12-31·CVSS 7.5
CVE-2004-2630 [HIGH] CVE-2004-2630: The MIME transformation system (transformations/text_plain__external
The MIME transformation system (transformations/text_plain__external.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.
Debian
CVE-2004-2630: phpmyadmin - The MIME transformation system (transformations/text_plain__external.inc.php) in...
vendor_debian·2004·CVSS 7.5
CVE-2004-2630 [HIGH] CVE-2004-2630: phpmyadmin - The MIME transformation system (transformations/text_plain__external.inc.php) in...
The MIME transformation system (transformations/text_plain__external.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.
Scope: local
bookworm: resolved (fixed in 2:2.6.0-pl2-1)
bullseye: resolved (fixed in 2:2.6.0-pl2-1)
forky: resolved (fixed in 2:2.6.0-pl2-1)
sid: resolved (fixed in 2:2.6.0-pl2-1)
trixie: resolved (fixed in 2:2.6.0-pl2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=109816584519779&w=2http://marc.info/?l=full-disclosure&m=109810251501643&w=2http://secunia.com/advisories/12813http://secunia.com/advisories/12859http://securitytracker.com/alerts/2004/Oct/1011761.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200410-14.xmlhttp://www.osvdb.org/10715http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2004-2http://www.securityfocus.com/bid/11391https://exchange.xforce.ibmcloud.com/vulnerabilities/17698http://marc.info/?l=bugtraq&m=109816584519779&w=2http://marc.info/?l=full-disclosure&m=109810251501643&w=2http://secunia.com/advisories/12813http://secunia.com/advisories/12859http://securitytracker.com/alerts/2004/Oct/1011761.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200410-14.xmlhttp://www.osvdb.org/10715http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2004-2http://www.securityfocus.com/bid/11391https://exchange.xforce.ibmcloud.com/vulnerabilities/17698
2004-12-31
Published