PHP CVE-2019-6799 Arbitrary File Read Vulnerability
BID:106736
CVE-2019-6799 |Info
PHP CVE-2019-6799 Arbitrary File Read Vulnerability
| Bugtraq ID: | 106736 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-6799 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 21 2019 12:00AM |
| Updated: | Jan 21 2019 12:00AM |
| Credit: | Tongqing Zhu@Knownsec 404 Team, Hongkun Zeng, and Hanno Bock |
| Vulnerable: |
phpMyAdmin phpMyAdmin 4.8.4 phpMyAdmin phpMyAdmin 4.8.3 phpMyAdmin phpMyAdmin 4.8.2 phpMyAdmin phpMyAdmin 4.8.1 phpMyAdmin phpMyAdmin 4.8 phpMyAdmin phpMyAdmin 4.7.8 phpMyAdmin phpMyAdmin 4.7.7 phpMyAdmin phpMyAdmin 4.7.6 phpMyAdmin phpMyAdmin 4.7.5 phpMyAdmin phpMyAdmin 4.7.4 phpMyAdmin phpMyAdmin 4.7.3 phpMyAdmin phpMyAdmin 4.7.2 phpMyAdmin phpMyAdmin 4.7.1 phpMyAdmin phpMyAdmin 4.7 phpMyAdmin phpMyAdmin 4.6.6 phpMyAdmin phpMyAdmin 4.6.5 phpMyAdmin phpMyAdmin 4.6.4 phpMyAdmin phpMyAdmin 4.6.2 phpMyAdmin phpMyAdmin 4.6.1 phpMyAdmin phpMyAdmin 4.6 phpMyAdmin phpMyAdmin 4.5.4 phpMyAdmin phpMyAdmin 4.5.2 phpMyAdmin phpMyAdmin 4.4.15 phpMyAdmin phpMyAdmin 4.4.13 phpMyAdmin phpMyAdmin 4.4.12 phpMyAdmin phpMyAdmin 4.4.11 phpMyAdmin phpMyAdmin 4.4.10 phpMyAdmin phpMyAdmin 4.4.9 phpMyAdmin phpMyAdmin 4.4.8 phpMyAdmin phpMyAdmin 4.4.7 phpMyAdmin phpMyAdmin 4.4.6 phpMyAdmin phpMyAdmin 4.4.5 phpMyAdmin phpMyAdmin 4.4.3 phpMyAdmin phpMyAdmin 4.4.2 phpMyAdmin phpMyAdmin 4.4.1 phpMyAdmin phpMyAdmin 4.4 phpMyAdmin phpMyAdmin 4.3.10 phpMyAdmin phpMyAdmin 4.2.11 phpMyAdmin phpMyAdmin 4.2.8 phpMyAdmin phpMyAdmin 4.2.6 phpMyAdmin phpMyAdmin 4.2.5 phpMyAdmin phpMyAdmin 4.2.4 phpMyAdmin phpMyAdmin 4.2.3 phpMyAdmin phpMyAdmin 4.2.2 phpMyAdmin phpMyAdmin 4.2.1 phpMyAdmin phpMyAdmin 4.2 phpMyAdmin phpMyAdmin 4.1.14 phpMyAdmin phpMyAdmin 4.1.13 phpMyAdmin phpMyAdmin 4.1.10 phpMyAdmin phpMyAdmin 4.1.9 phpMyAdmin phpMyAdmin 4.1.7 phpMyAdmin phpMyAdmin 4.1.6 phpMyAdmin phpMyAdmin 4.1.1 phpMyAdmin phpMyAdmin 4.1 phpMyAdmin phpMyAdmin 4.0.5 phpMyAdmin phpMyAdmin 4.0.4 phpMyAdmin phpMyAdmin 4.0.3 phpMyAdmin phpMyAdmin 4.0.2 phpMyAdmin phpMyAdmin 4.0.1 phpMyAdmin phpMyAdmin 4.0 phpMyAdmin phpMyAdmin 4.6.3 phpMyAdmin phpMyAdmin 4.5.5.1 phpMyAdmin phpMyAdmin 4.5.5.0 phpMyAdmin phpMyAdmin 4.5.3.1 phpMyAdmin phpMyAdmin 4.5.3.0 phpMyAdmin phpMyAdmin 4.5.1 phpMyAdmin phpMyAdmin 4.5.0.2 phpMyAdmin phpMyAdmin 4.5.0.1 phpMyAdmin phpMyAdmin 4.5.0 phpMyAdmin phpMyAdmin 4.5 phpMyAdmin phpMyAdmin 4.4.6.1 phpMyAdmin phpMyAdmin 4.4.6.0 phpMyAdmin phpMyAdmin 4.4.15.9 phpMyAdmin phpMyAdmin 4.4.15.8 phpMyAdmin phpMyAdmin 4.4.15.7 phpMyAdmin phpMyAdmin 4.4.15.6 phpMyAdmin phpMyAdmin 4.4.15.5 phpMyAdmin phpMyAdmin 4.4.15.4 phpMyAdmin phpMyAdmin 4.4.15.3 phpMyAdmin phpMyAdmin 4.4.15.2 phpMyAdmin phpMyAdmin 4.4.15.10 phpMyAdmin phpMyAdmin 4.4.15.1 phpMyAdmin phpMyAdmin 4.4.14.1 phpMyAdmin phpMyAdmin 4.4.14 phpMyAdmin phpMyAdmin 4.4.13.1 phpMyAdmin phpMyAdmin 4.4.1.1 phpMyAdmin phpMyAdmin 4.3.9 phpMyAdmin phpMyAdmin 4.3.8 phpMyAdmin phpMyAdmin 4.3.7 phpMyAdmin phpMyAdmin 4.3.6 phpMyAdmin phpMyAdmin 4.3.5 phpMyAdmin phpMyAdmin 4.3.13.2 phpMyAdmin phpMyAdmin 4.3.13.1 phpMyAdmin phpMyAdmin 4.3.11.1 phpMyAdmin phpMyAdmin 4.3.11 phpMyAdmin phpMyAdmin 4.3.1 phpMyAdmin phpMyAdmin 4.3.0 phpMyAdmin phpMyAdmin 4.2.9.1 phpMyAdmin phpMyAdmin 4.2.8.1 phpMyAdmin phpMyAdmin 4.2.7.1 phpMyAdmin phpMyAdmin 4.2.13.3 phpMyAdmin phpMyAdmin 4.2.13.2 phpMyAdmin phpMyAdmin 4.2.13.1 phpMyAdmin phpMyAdmin 4.2.12 phpMyAdmin phpMyAdmin 4.2.10.1 phpMyAdmin phpMyAdmin 4.1.8 phpMyAdmin phpMyAdmin 4.1.5 phpMyAdmin phpMyAdmin 4.1.3 phpMyAdmin phpMyAdmin 4.1.2 phpMyAdmin phpMyAdmin 4.1.14.8 phpMyAdmin phpMyAdmin 4.1.14.7 phpMyAdmin phpMyAdmin 4.1.14.6 phpMyAdmin phpMyAdmin 4.1.14.5 phpMyAdmin phpMyAdmin 4.1.14.4 phpMyAdmin phpMyAdmin 4.1.14.3 phpMyAdmin phpMyAdmin 4.1.14.2 phpMyAdmin phpMyAdmin 4.1.14.1 phpMyAdmin phpMyAdmin 4.1.11 phpMyAdmin phpMyAdmin 4.0.9 phpMyAdmin phpMyAdmin 4.0.8 phpMyAdmin phpMyAdmin 4.0.7 phpMyAdmin phpMyAdmin 4.0.6 phpMyAdmin phpMyAdmin 4.0.4.2 phpMyAdmin phpMyAdmin 4.0.4.1 phpMyAdmin phpMyAdmin 4.0.10.9 phpMyAdmin phpMyAdmin 4.0.10.8 phpMyAdmin phpMyAdmin 4.0.10.7 phpMyAdmin phpMyAdmin 4.0.10.6 phpMyAdmin phpMyAdmin 4.0.10.5 phpMyAdmin phpMyAdmin 4.0.10.4 phpMyAdmin phpMyAdmin 4.0.10.3 phpMyAdmin phpMyAdmin 4.0.10.20 phpMyAdmin phpMyAdmin 4.0.10.2 phpMyAdmin phpMyAdmin 4.0.10.19 phpMyAdmin phpMyAdmin 4.0.10.18 phpMyAdmin phpMyAdmin 4.0.10.17 phpMyAdmin phpMyAdmin 4.0.10.16 phpMyAdmin phpMyAdmin 4.0.10.15 phpMyAdmin phpMyAdmin 4.0.10.14 phpMyAdmin phpMyAdmin 4.0.10.13 phpMyAdmin phpMyAdmin 4.0.10.12 phpMyAdmin phpMyAdmin 4.0.10.11 phpMyAdmin phpMyAdmin 4.0.10.10 phpMyAdmin phpMyAdmin 4.0.10.1 phpMyAdmin phpMyAdmin 4.0.10 PHP PHP 7.1.26 |
| Not Vulnerable: |
phpMyAdmin phpMyAdmin 4.8.5 PHP PHP 7.3.1 |
Discussion
PHP CVE-2019-6799 Arbitrary File Read Vulnerability
PHP is prone to a security vulnerability that allows remote attackers to read arbitrary files.
Successful exploits may allow an attacker to obtain sensitive information that may lead to further attacks.
phpMyAdmin 4.0 through 4.8.4 are vulnerable.
PHP is prone to a security vulnerability that allows remote attackers to read arbitrary files.
Successful exploits may allow an attacker to obtain sensitive information that may lead to further attacks.
phpMyAdmin 4.0 through 4.8.4 are vulnerable.
Exploit / POC
PHP CVE-2019-6799 Arbitrary File Read Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
PHP CVE-2019-6799 Arbitrary File Read Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.