Back
CVE-2005-3299
PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array.
Published: Oct 23, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| phpmyadmin | phpmyadmin | 2.6.4 |
| phpmyadmin | phpmyadmin | 2.6.4_pl1 |
GitHub Security Advisory GHSA-xq8v-3x6g-9vpm
PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows...
References (10)
- http://secunia.com/advisories/17137 Patch, Vendor Advisory
- http://securityreason.com/securityalert/69
- http://www.gentoo.org/security/en/glsa/glsa-200510-16.xml Patch, Vendor Advisory
- http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2005-4 Patch, Vendor Advisory
- http://www.securityfocus.com/bid/15053
- http://secunia.com/advisories/17137 Patch, Vendor Advisory
- http://securityreason.com/securityalert/69
- http://www.gentoo.org/security/en/glsa/glsa-200510-16.xml Patch, Vendor Advisory
- http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2005-4 Patch, Vendor Advisory
- http://www.securityfocus.com/bid/15053
Risk Scores
CVSS Score
5.0 / 10
EPSS Score
15.92%
Top 3% most likely to be exploited
Threat Score
24.8 / 100
Data Sources
NVD
EPSS
GitHub