CVE-2019-6799 is a local file inclusion vulnerability in phpMyAdmin versions prior to 4.8.5, affecting Debian and phpMyAdmin products. When the AllowArbitraryServer setting is enabled, a malicious MySQL server can be used to read arbitrary files on the web server. This medium severity vulnerability (CVSS 5.9) has a high impact on confidentiality, requiring high attack complexity but no user interaction. While there is no evidence of active exploitation or Metasploit modules, a Nuclei template exists, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, <= 4.8.4CPE matchmatch criteria | cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.