PT-2018-1938 · Phpmyadmin+2 · Phpmyadmin+2
Henry Huang
·
Published
2018-06-19
·
Updated
2025-12-15
·
CVE-2018-12613
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
phpMyAdmin versions 4.8.0 through 4.8.1
Description
An issue was discovered in phpMyAdmin where an attacker can include and potentially execute files on the server due to improper testing for whitelisted pages during page redirection and loading within phpMyAdmin. The attacker must be authenticated, except in cases where
$cfg['AllowArbitraryServer'] = true or $cfg['ServerDefault'] = 0, which can bypass login requirements or allow arbitrary code execution.Recommendations
For phpMyAdmin versions 4.8.0 through 4.8.1, update to version 4.8.2 or later to resolve the issue.
As a temporary workaround, consider disabling the
$cfg['AllowArbitraryServer'] and $cfg['ServerDefault'] = 0 configurations to minimize the risk of exploitation.
Restrict access to sensitive files and directories on the server to prevent potential execution by an attacker.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Suse
Phpmyadmin