Description
Multiple PHP remote file inclusion vulnerabilities in phpMyAdmin 2.6.1 allow remote attackers to execute arbitrary PHP code by modifying the (1) theme parameter to phpmyadmin.css.php or (2) cfg[Server][extension] parameter to database_interface.lib.php to reference a URL on a remote web server that contains the code.
Remediation
References
Related Vulnerabilities
WordPress Plugin Elementor Addon Elements Multiple Cross-Site Scripting Vulnerabilities (1.11.1)
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-5835)
MySQL CVE-2016-5444 Vulnerability (CVE-2016-5444)
Apache HTTP Server Other Vulnerability (CVE-1999-0107)
Oracle Database Server SYS Account privilege issue (CVE-2021-2000)