Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-19968

Опубликовано: 11 дек. 2018
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.8.4 (исключая)
Конфигурация 2
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

EPSS

Процентиль: 83%
0.02067
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 6 лет назад

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system.

CVSS3: 6.5
debian
больше 6 лет назад

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents o ...

CVSS3: 6.5
github
около 3 лет назад

phpMyAdmin Local file inclusion through transformation feature

suse-cvrf
больше 6 лет назад

Security update for phpMyAdmin

suse-cvrf
больше 6 лет назад

Security update for phpMyAdmin

EPSS

Процентиль: 83%
0.02067
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200