Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2019-6799Path Traversal in Phpmyadmin

CWE-22Path Traversal11 documents8 sources
Severity
5.9MEDIUMNVD
OSV6.5
EPSS
76.6%
top 1.05%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJan 26
Latest updateMay 13

Description

An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. This is related to the mysql.allow_local_infile PHP configuration, and the inadvertent ignoring of "options(MYSQLI_OPT_LOCAL_INFILE" calls.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages5 packages

debiandebian/phpmyadmin< phpmyadmin 4:4.9.1+dfsg1-2 (bookworm)
Packagistphpmyadmin/phpmyadmin4.84.8.5
Debianphpmyadmin/phpmyadmin< 4:4.9.1+dfsg1-2+3
Ubuntuphpmyadmin/phpmyadmin< 4:4.6.6-5ubuntu0.5
NVDphpmyadmin/phpmyadmin4.0.04.8.4

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

4
OSV
phpMyAdmin Arbitrary file read vulnerability2022-05-13
GHSA
phpMyAdmin Arbitrary file read vulnerability2022-05-13
OSV
phpmyadmin vulnerabilities2020-11-19
OSV
CVE-2019-6799: An issue was discovered in phpMyAdmin before 42019-01-26

💥Exploits & PoCs

1
Nuclei
phpMyAdmin <4.8.5 - Local File Inclusion

📋Vendor Advisories

2
Ubuntu
phpMyAdmin vulnerabilities2020-11-19
Debian
CVE-2019-6799: phpmyadmin - An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServe...2019

🕵️Threat Intelligence

1
Greynoiseio
NoiseLetter February 2026

💬Community

2
Bugzilla
CVE-2019-6798 CVE-2019-6799 phpMyAdmin: Multiple issues fixed in 4.8.5 version [epel-all]2019-01-31
Bugzilla
CVE-2019-6798 CVE-2019-6799 phpMyAdmin: Multiple issues fixed in 4.8.5 version2019-01-31