[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2018-19968 -- phpmyadmin

ID: oval:org.secpod.oval:def:2000690Date: (C)2019-05-30   (M)2023-02-08
Class: VULNERABILITYFamily: unix




An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system.

Platform:
Debian 8.x
Debian 9.x
Product:
phpmyadmin
Reference:
CVE-2018-19968
CVE    1
CVE-2018-19968
CPE    244
cpe:/a:phpmyadmin:phpmyadmin:4.5.0:rc1
cpe:/a:phpmyadmin:phpmyadmin:4.3.1
cpe:/a:phpmyadmin:phpmyadmin:4.3.2
cpe:/a:phpmyadmin:phpmyadmin:4.3.0
...

© SecPod Technologies