WRITEUP

WRITEUP
Exploit for CVE-2019-19617 - phpMyAdmin <4.9.2 - Info Disclosure
AI Analysis

This patch addresses a cross-site scripting (XSS) vulnerability in phpMyAdmin by properly escaping Git revision information displayed on the index page. The fix ensures that user-controlled data (commit hash, branch names) is sanitized using htmlspecialchars before being rendered in HTML context.

Attack Type
XSS
Complexity
trivial
Reliability
reliable
MITRE ATT&CK
T1059.007 - JavaScript
Loading exploit code...
Download ZIP Password: eip
Vulnerability
CVE-2019-19617
phpMyAdmin <4.9.2 - Info Disclosure
CRITICAL
CVSS 9.8