[3.9] phpmyadmin: Multiple vulnerabilities (CVE-2018-12581, CVE-2018-12613)
CVE-2018-12581: XSS in Designer feature
A Cross-Site Scripting vulnerability was found in the Designer feature,
where an attacker can
deliver a payload to a user through a specially-crafted database name.
phpMyAdmin versions prior to 4.8.2.
CVE-2018-12613: File inclusion and remote code execution attack
A flaw has been discovered where an attacker can include (view and
potentially execute) files on the server.
The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages.
An attacker must be authenticated, except in these situations:
- $cfg[‘AllowArbitraryServer’] = true: attacker can specify any host he/she is already in control of, and execute arbitrary code on phpMyAdmin
- $cfg[‘ServerDefault’] = 0: this bypasses the login and runs the vulnerable code without any authentication
phpMyAdmin 4.8.0 and 4.8.1 are affected.
(from redmine: issue id 9092, created on 2018-07-16, closed on 2018-07-17)
- Revision 7b247d9a by Natanael Copa on 2018-07-16T17:52:52Z:
community/phpmyadmin: security upgrade to 4.8.2 (CVE-2018-12581,CVE-2018-12613) fixes #9092