phpMyAdmin CVE-2014-8959 Local File Include Vulnerability
BID:71247
Info
phpMyAdmin CVE-2014-8959 Local File Include Vulnerability
| Bugtraq ID: | 71247 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-8959 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 20 2014 12:00AM |
| Updated: | Jul 15 2015 12:20AM |
| Credit: | Johannes Dahse |
| Vulnerable: |
Gentoo Linux |
| Not Vulnerable: | |
Discussion
phpMyAdmin CVE-2014-8959 Local File Include Vulnerability
phpMyAdmin is prone to a local file-include vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to obtain potentially sensitive information and execute arbitrary local scripts. This could allow the attacker to compromise the application and the computer; other attacks are also possible.
phpMyAdmin 4.0.x prior to 4.0.10.6, 4.1.x prior to 4.1.14.7 and 4.2.x prior to 4.2.12 are vulnerable.
phpMyAdmin is prone to a local file-include vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to obtain potentially sensitive information and execute arbitrary local scripts. This could allow the attacker to compromise the application and the computer; other attacks are also possible.
phpMyAdmin 4.0.x prior to 4.0.10.6, 4.1.x prior to 4.1.14.7 and 4.2.x prior to 4.2.12 are vulnerable.
Exploit / POC
phpMyAdmin CVE-2014-8959 Local File Include Vulnerability
An attacker can exploit this issue using a browser.
An attacker can exploit this issue using a browser.
References
phpMyAdmin CVE-2014-8959 Local File Include Vulnerability
References:
References:
- phpMyAdmin Homepage (phpMyAdmin)