[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

[3.8] phpmyadmin: Multiple vulnerabilities (CVE-2018-19968, CVE-2018-19969, CVE-2018-19970)

ID: oval:org.secpod.oval:def:1801276Date: (C)2019-01-16   (M)2021-09-12
Class: PATCHFamily: unix




CVE-2018-19968: Local file inclusion through transformation feature.¶ A flaw has been found where an attacker can exploit phpMyAdmin to leak the contents of a local file. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system. Affected Versions:¶ phpMyAdmin versions from at least 4.0 through 4.8.3 are affected

Platform:
Alpine Linux 3.8
Product:
phpmyadmin
Reference:
9786
CVE-2018-19968
CVE-2018-19969
CVE-2018-19970
CVE    3
CVE-2018-19970
CVE-2018-19969
CVE-2018-19968
CPE    242
cpe:/a:phpmyadmin:phpmyadmin:4.5.0:rc1
cpe:/a:phpmyadmin:phpmyadmin:4.3.1
cpe:/a:phpmyadmin:phpmyadmin:4.3.2
cpe:/a:phpmyadmin:phpmyadmin:4.3.0
...

© SecPod Technologies