Exploitation Summary
CVE-2019-6799 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.
Description
An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. This is related to the mysql.allow_local_infile PHP configuration, and the inadvertent ignoring of "options(MYSQLI_OPT_LOCAL_INFILE" calls.
Nuclei Templates (1)
phpMyAdmin <4.8.5 - Local File Inclusion
MEDIUMVERIFIEDby pwnhxl
Shodan:
title:"phpmyadmin" || http.title:"phpmyadmin" || http.component:"phpmyadmin" || cpe:"cpe:2.3:a:phpmyadmin:phpmyadmin"
FOFA:
body="pma_servername" && body="4.8.4" || title="phpmyadmin"
References (3)
Core 3
Core References
Mitigation, Patch, Vendor Advisory x_refsource_confirm
https://www.phpmyadmin.net/security/PMASA-2019-1/
Mailing List, Third Party Advisory mailing-list
x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2019/02/msg00039.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/106736
Scores
CVSS v3
5.9
EPSS
0.1559
EPSS Percentile
96.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
Status
published
Products (3)
debian/debian_linux
8.0
phpmyadmin/phpmyadmin
4.0.0 - 4.8.4
phpmyadmin/phpmyadmin
4.8 - 4.8.5Packagist
Published
Jan 26, 2019
Tracked Since
Feb 18, 2026