{"id":"CVE-2018-12613","details":"An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages. An attacker must be authenticated, except in the \"$cfg['AllowArbitraryServer'] = true\" case (where an attacker can specify any host he/she is already in control of, and execute arbitrary code on phpMyAdmin) and the \"$cfg['ServerDefault'] = 0\" case (which bypasses the login requirement and runs the vulnerable code without any authentication).","aliases":["GHSA-x394-g9j8-x7mf"],"modified":"2026-07-08T17:57:30.373827Z","published":"2018-06-21T20:29:00.327Z","related":["openSUSE-SU-2024:11171-1"],"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/104532"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201904-16"},{"type":"ADVISORY","url":"https://www.exploit-db.com/exploits/44928/"},{"type":"ADVISORY","url":"https://www.phpmyadmin.net/security/PMASA-2018-4/"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/164623/phpMyAdmin-4.8.1-Remote-Code-Execution.html"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/44924/"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/45020/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/phpmyadmin/phpmyadmin","events":[{"introduced":"9d6ac04ae8cd7064c28c93a6a949cb5324899593"},{"fixed":"3115f340b933ab95e75785af02d6d497a04f47b3"}],"database_specific":{"cpe":"cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.8.0"},{"fixed":"4.8.2"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-12613.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}