CVE-2018-19968

Name
CVE-2018-19968
Description
An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch https://www.phpmyadmin.net/security/PMASA-2018-6/
Third Party Advisory http://www.securityfocus.com/bid/106178
Mailing List https://lists.debian.org/debian-lts-announce/2019/02/msg00003.html
Third Party Advisory https://security.gentoo.org/glsa/201904-16

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:* phpmyadmin >= 4.0.0 < 4.8.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
phpmyadmin edge-community 4.8.4-r0 None fixed
phpmyadmin edge-community 4.8.2-r0 None possibly vulnerable
phpmyadmin edge-community 4.8.0.-r1 None possibly vulnerable
phpmyadmin edge-community 4.8.0-r1 None possibly vulnerable
phpmyadmin edge-community 4.6.5.2-r0 None possibly vulnerable
phpmyadmin 3.22-community 4.8.4-r0 None fixed
phpmyadmin 3.22-community 4.8.2-r0 None possibly vulnerable
phpmyadmin 3.22-community 4.8.0-r1 None possibly vulnerable
phpmyadmin 3.22-community 4.6.5.2-r0 None possibly vulnerable
phpmyadmin 3.21-community 4.8.4-r0 None fixed
phpmyadmin 3.20-community 4.8.4-r0 None fixed
phpmyadmin 3.19-community 4.8.4-r0 None fixed
phpmyadmin 3.18-community 4.8.4-r0 None fixed
phpmyadmin 3.17-community 4.8.4-r0 None fixed