Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-19968

Опубликовано: 11 дек. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 4
CVSS3: 6.5

Описание

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system.

РелизСтатусПримечание
bionic

released

4:4.6.6-5ubuntu0.5
cosmic

ignored

end of life
devel

not-affected

4:4.9.2+dfsg1-1
disco

ignored

end of life
eoan

DNE

esm-apps/bionic

released

4:4.6.6-5ubuntu0.5
esm-apps/focal

not-affected

4:4.9.2+dfsg1-1
esm-apps/jammy

not-affected

4:4.9.2+dfsg1-1
esm-apps/xenial

released

4:4.5.4.1-2ubuntu2.1+esm6
esm-infra-legacy/trusty

not-affected

4:4.0.10-1ubuntu0.1+esm4

Показывать по

4 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
почти 7 лет назад

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system.

CVSS3: 6.5
debian
почти 7 лет назад

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents o ...

CVSS3: 6.5
github
больше 3 лет назад

phpMyAdmin Local file inclusion through transformation feature

suse-cvrf
почти 7 лет назад

Security update for phpMyAdmin

suse-cvrf
почти 7 лет назад

Security update for phpMyAdmin

4 Medium

CVSS2

6.5 Medium

CVSS3