Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13272
HistoryJan 28, 2019 - 3:10 a.m.

Arbitrary File Read

2019-01-2803:10:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

EPSS

0.119

Percentile

95.4%

phpmyadmin is vulnerable to arbitrary file read. An attacker is able to read any file on the server using a rogue MySQL server, when AllowArbitraryServer is set to true or when mysql.allow_local_infile is enabled by default. This is due to a bug in PHP, which does not honor phpMyadmin attempts to block the use of LOAD DATA INFILE.