Title : phpMyAdmin "sort_by" Parameter PHP Code Injection Vulnerability VUPEN ID : VUPEN/ADV-2008-2585 CVE ID : CVE-2008-4096 CWE ID : CWE-94
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-09-16
Technical Description
A vulnerability has been identified in phpMyAdmin, which could be exploited by malicious users to execute arbitrary code. This issue is caused by an input validation error in the "server_databases.php" script that does not validate the "sort_by" parameter, which could be exploited by authenticated attackers to inject and execute arbitrary PHP code with the privileges of the web server.