CVE-2019-6799
MEDIUM NUCLEIphpMyAdmin <4.8.5 - Info Disclosure
Title source: llmDescription
An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. This is related to the mysql.allow_local_infile PHP configuration, and the inadvertent ignoring of "options(MYSQLI_OPT_LOCAL_INFILE" calls.
Nuclei Templates (1)
phpMyAdmin <4.8.5 - Local File Inclusion
MEDIUMVERIFIEDby pwnhxl
Shodan:
title:"phpmyadmin" || http.title:"phpmyadmin" || http.component:"phpmyadmin" || cpe:"cpe:2.3:a:phpmyadmin:phpmyadmin"
FOFA:
body="pma_servername" && body="4.8.4" || title="phpmyadmin"
Scores
CVSS v3
5.9
EPSS
0.7658
EPSS Percentile
98.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
Status
published
Affected Products (3)
phpmyadmin/phpmyadmin
< 4.8.4
debian/debian_linux
phpmyadmin/phpmyadmin
< 4.8.5Packagist
Timeline
Published
Jan 26, 2019
Tracked Since
Feb 18, 2026