phpMyAdmin是phpMyAdmin团队开发的一套免费的、基于Web的MySQL数据库管理工具。该工具能够创建和删除数据库,创建、删除、修改数据库表,执行SQL脚本命令等。 phpMyAdmin 4.8.2之前的4.8.x版本中存在安全漏洞。攻击者可利用该漏洞包含(查看并可能执行)服务器上的文件。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | PHPMyAdmin v4.8.0 and v.4.8.1 LFI exploit | https://github.com/0x00-0x00/CVE-2018-12613 | POC详情 |
| 2 | Modified standalone exploit ported for Python 3 | https://github.com/ivanitlearning/CVE-2018-12613 | POC详情 |
| 3 | 这篇文章将分享一个phpMyAdmin 4.8.1版本的文件包含漏洞,从配置到原理,再到漏洞复现进行讲解,更重要的是让大家了解这些真实漏洞背后的知识。基础性文章,希望对您有所帮助! | https://github.com/eastmountyxz/CVE-2018-12613-phpMyAdmin | POC详情 |
| 4 | PhpMyAdmin before version 4.8.2 is susceptible to local file inclusion that allows an attacker to include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages. An attacker must be authenticated, except in the "$cfg['AllowArbitraryServer'] = true" case (where an attacker can specify any host he/she is already in control of, and execute arbitrary code on phpMyAdmin) and the "$cfg['ServerDefault'] = 0" case (which bypasses the login requirement and runs the vulnerable code without any authentication). | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-12613.yaml | POC详情 |
| 5 | None | https://github.com/chaitin/xray-plugins/blob/main/poc/manual/phpmyadmin-cve-2018-12613-file-inclusion.yml | POC详情 |
| 6 | https://github.com/vulhub/vulhub/blob/master/phpmyadmin/CVE-2018-12613/README.md | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2018-0306 | 多款Cisco产品NX-OS Software CLI解析器输入验证错误漏洞 | |
| CVE-2018-0373 | Cisco AnyConnect Secure Mobility Client for Windows Desktop 输入验证漏洞 | |
| CVE-2018-0371 | Cisco Acano X-Series、Meeting Server 1000和Meeting Server 2000 Web Admin Interface 输入验证漏洞 | |
| CVE-2018-0365 | Cisco Firepower Management Center 跨站请求伪造漏洞 | |
| CVE-2018-0364 | Cisco Unified Communications Domain Manager 跨站请求伪造漏洞 | |
| CVE-2018-0363 | Cisco Unified Communications Manager IM & Presence Service 跨站请求伪造漏洞 | |
| CVE-2018-0362 | Cisco 5000 Series Enterprise Network Compute System和UCS E-Series Servers 授权问题漏洞 | |
| CVE-2018-0359 | Cisco Meeting Server 安全漏洞 | |
| CVE-2018-0358 | Cisco TelePresence Video Communication Server Expressway 安全漏洞 | |
| CVE-2018-0337 | Cisco NX-OS Software 输入验证错误漏洞 | |
| CVE-2018-0331 | 多款Cisco产品NX-OS Software Discovery Protocol子系统资源管理错误漏洞 | |
| CVE-2018-0313 | 多款Cisco产品NX-OS Software 输入验证漏洞 | |
| CVE-2018-0311 | 多款Cisco产品FXOS Software和NX-OS Software Fabric Services组件资源管理错误漏洞 | |
| CVE-2018-0310 | 多款Cisco产品FXOS Software和NX-OS Software Fabric Services组件资源管理错误漏洞 | |
| CVE-2018-0309 | Cisco Nexus 3000和9000 Series Switches NX-OS 安全漏洞 | |
| CVE-2018-12630 | NEWMARK NMCMS SQL注入漏洞 | |
| CVE-2018-0305 | 多款Cisco产品FXOS Software和NX-OS Software Fabric Services组件安全漏洞 | |
| CVE-2018-0303 | 多款Cisco产品FXOS Software和NX-OS Software Discovery Protocol组件输入验证漏洞 | |
| CVE-2018-0302 | 多款Cisco产品FXOS Software和UCS Fabric Interconnect Software CLI解析器输入验证错误漏洞 | |
| CVE-2018-0300 | Cisco Firepower 4100 Series Next-Generation Firewall和Firepower 9300 Security Appliance 路径遍 |
显示前 20 条,共 30 条。 查看全部 → →
暂无评论