Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xc97-r49q-cxgc

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

phpMyAdmin Local file inclusion through transformation feature

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system.

Пакеты

Наименование

phpmyadmin/phpmyadmin

composer
Затронутые версииВерсия исправления

< 4.8.4

4.8.4

EPSS

Процентиль: 85%
0.02691
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 6 лет назад

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system.

CVSS3: 6.5
nvd
больше 6 лет назад

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system.

CVSS3: 6.5
debian
больше 6 лет назад

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents o ...

suse-cvrf
больше 6 лет назад

Security update for phpMyAdmin

suse-cvrf
больше 6 лет назад

Security update for phpMyAdmin

EPSS

Процентиль: 85%
0.02691
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200