V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2018-12613
DEB
HighConfirmedExploit available

An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the serv…

CVSS
8.8
High
EPSS
0.94
p99
Published
2018-01-01
Updated
2018-01-01
Description

An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages. An attacker must be authenticated, except in the "$cfg['AllowArbitraryServer'] = true" case (where an attacker can specify any host he/she is already in control of, and execute arbitrary code on phpMyAdmin) and the "$cfg['ServerDefault'] = 0" case (which bypasses the login requirement and runs the vulnerable code without any authentication).

Tags · CWE
CWE-287
CAPEC-22
CAPEC-57
CAPEC-94
CAPEC-114
CAPEC-115
CAPEC-151
CAPEC-194
CAPEC-593
CAPEC-633
CAPEC-650
Affected products
Phpmyadmin 4.8.0–4.8.2
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Timeline
2018-01-01
Published
2018-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.943 · p99
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-57 · CWE-287
└ via CAPEC-633 · CWE-287
└ via CAPEC-593 · CWE-287
└ via CAPEC-650 · CWE-287
└ via CAPEC-114 · CWE-287
└ via CAPEC-593 · CWE-287
└ via CAPEC-94 · CWE-287
└ via CAPEC-593 · CWE-287
Known exploits — Сканер-ВС
44924
exploitdb · https://www.exploit-db.com/exploits/44924
Enterprise
44928
exploitdb · https://www.exploit-db.com/exploits/44928
Enterprise
45020
exploitdb · https://www.exploit-db.com/exploits/45020
Enterprise
50457
exploitdb · https://www.exploit-db.com/exploits/50457
Enterprise
CVE-2018-12613
github-poc · https://github.com/eastmountyxz/CVE-2018-12613-phpMyAdmin
Enterprise
Affected software
ProductVendorStatus
phpmyadminTracked
phpmyadminTracked
phpmyadminTracked
phpmyadminTracked
phpmyadminTracked
phpmyadmin*Tracked
Source databases
DEB
CVE
UBU
Related vulnerabilities