CVE-2018-12613
82Vexday Risk Score
Corrija agora. Ela exploração observada pelo VulnCheck e tem exploit funcional público.
ssvc Actepss 98%
da publicação à arma0 dias
Publicada no NVD21 de jun.
1ª PoC21 de jun.
metasploit19 de jun.
VulnCheck+1629d
probabilidade de exploração
98%top 1% das CVEs
exploração observada
simVulnCheck
14 exploit(s) público(s)
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages. An attacker must be authenticated, except in the "$cfg['AllowArbitraryServer'] = true" case (where an attacker can specify any host he/she is already in control of, and execute arbitrary code on phpMyAdmin) and the "$cfg['ServerDefault'] = 0" case (which bypasses the login requirement and runs the vulnerable code without any authentication).
Produtos afetados
n/a · n/aPoCs públicas encontradas — 14✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/45020exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/50457exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/44928exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/44924githubgithub.com/0x00-0x00/CVE-2018-12613★ 10githubgithub.com/ivanitlearning/CVE-2018-12613★ 4githubgithub.com/eastmountyxz/CVE-2018-12613-phpMyAdmin★ 2cve_referencewww.exploit-db.com/exploits/44924/não verificadovulncheckvulncheck.com/xdb/0364334e6702não verificadovulncheckvulncheck.com/xdb/1bf5460a7dbenão verificadocve_referencewww.exploit-db.com/exploits/44928/não verificadovulncheckvulncheck.com/xdb/103733d6a228não verificadocve_referencepacketstormsecurity.com/files/164623/phpMyAdmin-4.8.1-Remote-Code-Execution.htmlnão verificadocve_referencewww.exploit-db.com/exploits/45020/não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Referências
http://packetstormsecurity.com/files/164623/phpMyAdmin-4.8.1-Remote-Code-Execution.htmlhttps://security.gentoo.org/glsa/201904-16https://www.exploit-db.com/exploits/44924/https://www.exploit-db.com/exploits/44928/https://www.exploit-db.com/exploits/45020/https://www.phpmyadmin.net/security/PMASA-2018-4/http://www.securityfocus.com/bid/104532