Vulnerability Details CVE-2004-1148
phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 59.1%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2004-1148
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.4.0
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.0
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.2
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.4
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.5
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.5_pl1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.5_rc1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.5_rc2
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.6_rc1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.7
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.7_pl1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.6.0_pl1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.6.0_pl2
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.6.0_pl3