CVE-2019-6799

MEDIUM NUCLEI

phpMyAdmin <4.8.5 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2019-6799 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. This is related to the mysql.allow_local_infile PHP configuration, and the inadvertent ignoring of "options(MYSQLI_OPT_LOCAL_INFILE" calls.

Nuclei Templates (1)

phpMyAdmin <4.8.5 - Local File Inclusion
MEDIUMVERIFIEDby pwnhxl
Shodan: title:"phpmyadmin" || http.title:"phpmyadmin" || http.component:"phpmyadmin" || cpe:"cpe:2.3:a:phpmyadmin:phpmyadmin"
FOFA: body="pma_servername" && body="4.8.4" || title="phpmyadmin"

References (3)

Core 3
Core References
Mitigation, Patch, Vendor Advisory x_refsource_confirm
https://www.phpmyadmin.net/security/PMASA-2019-1/
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2019/02/msg00039.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106736

Scores

CVSS v3 5.9
EPSS 0.1559
EPSS Percentile 96.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (3)
debian/debian_linux 8.0
phpmyadmin/phpmyadmin 4.0.0 - 4.8.4
phpmyadmin/phpmyadmin 4.8 - 4.8.5Packagist
Published Jan 26, 2019
Tracked Since Feb 18, 2026