Bug #9091: phpmyadmin: Multiple vulnerabilities (CVE-2018-12581, CVE-2018-12613)
[3.8] phpmyadmin: Multiple vulnerabilities (CVE-2018-12581, CVE-2018-12613)
CVE-2018-12581: XSS in Designer feature¶
A Cross-Site Scripting vulnerability was found in the Designer feature, where an attacker can
deliver a payload to a user through a specially-crafted database name.
phpMyAdmin versions prior to 4.8.2.
CVE-2018-12613: File inclusion and remote code execution attack¶A flaw has been discovered where an attacker can include (view and potentially execute) files on the server.
The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages.
An attacker must be authenticated, except in these situations:
- $cfg['AllowArbitraryServer'] = true: attacker can specify any host he/she is already in control of, and execute arbitrary code on phpMyAdmin
- $cfg['ServerDefault'] = 0: this bypasses the login and runs the vulnerable code without any authentication
phpMyAdmin 4.8.0 and 4.8.1 are affected.