CVE-2018-19968
Summary
| CVE | CVE-2018-19968 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-12-11 17:29:00 UTC |
| Updated | 2019-04-23 12:36:00 UTC |
| Description | An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| phpMyAdmin - Security - PMASA-2018-6 |
CONFIRM |
www.phpmyadmin.net |
Patch, Vendor Advisory |
| [SECURITY] [DLA 1658-1] phpmyadmin security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| phpMyAdmin CVE-2018-19968 Local File Include Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| phpMyAdmin: Multiple vulnerabilities (GLSA 201904-16) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 501152 Alpine Linux Security Update for phpmyadmin
- 710168 Gentoo Linux phpMyAdmin Multiple vulnerabilities (GLSA 201904-16)