Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-6799

Опубликовано: 26 янв. 2019
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3
CVSS3: 5.9

Описание

An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. This is related to the mysql.allow_local_infile PHP configuration, and the inadvertent ignoring of "options(MYSQLI_OPT_LOCAL_INFILE" calls.

РелизСтатусПримечание
bionic

released

4:4.6.6-5ubuntu0.5
cosmic

ignored

end of life
devel

not-affected

4:4.9.2+dfsg1-1
disco

ignored

end of life
eoan

DNE

esm-apps/bionic

released

4:4.6.6-5ubuntu0.5
esm-apps/focal

not-affected

4:4.9.2+dfsg1-1
esm-apps/jammy

not-affected

4:4.9.2+dfsg1-1
esm-apps/noble

not-affected

4:4.9.2+dfsg1-1
esm-apps/xenial

needed

Показывать по

4.3 Medium

CVSS2

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
больше 6 лет назад

An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. This is related to the mysql.allow_local_infile PHP configuration, and the inadvertent ignoring of "options(MYSQLI_OPT_LOCAL_INFILE" calls.

CVSS3: 5.9
debian
больше 6 лет назад

An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbi ...

CVSS3: 5.9
github
около 3 лет назад

phpMyAdmin Arbitrary file read vulnerability

suse-cvrf
больше 6 лет назад

Security update for phpMyAdmin

4.3 Medium

CVSS2

5.9 Medium

CVSS3