Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2005-3300

Published: 23 October 2005

The register_globals emulation layer in grab_globals.php for phpMyAdmin before 2.6.4-pl3 does not perform safety checks on values in the _FILES array for uploaded files, which allows remote attackers to include arbitrary files by using direct requests to library scripts that do not use grab_globals.php, then modifying certain configuration values for the theme.

Priority

Unknown

Status

Package Release Status
phpmyadmin
Launchpad, Ubuntu, Debian
dapper
Released (2.8.0.3-1)
edgy
Released (2.8.0.3-1)
feisty
Released (2.8.0.3-1)
upstream Needs triage