S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2018-12613 Scanner

CVE-2018-12613 scanner - Remote File Inclusion (RFI) vulnerability in phpMyAdmin

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-12613
8.8
CVSS

An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages. An attacker must be authenticated, except in the "$cfg['AllowArbitraryServer'] = true" case (where an attacker can specify any host he/she is already in control of, and execute arbitrary code on phpMyAdmin) and the "$cfg['ServerDefault'] = 0" case (which bypasses the login requirement and runs the vulnerable code without any authentication).

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

PhpMyAdmin is a web-based database management tool. It is an open-source program written in PHP language that allows users to manage and manipulate databases. The purpose of PhpMyAdmin is to provide an easy-to-use interface for users to manage their databases without the need for specialized knowledge in databases.

CVE-2018-12613 is a vulnerability that was discovered in the PhpMyAdmin 4.8.x version, which allowed an attacker to include files on the server. The vulnerability resulted from an incomplete test for whitelisted pages, making it possible for an attacker to execute arbitrary code while being authenticated. The vulnerability becomes more severe in the "$cfg['AllowArbitraryServer'] = true" and "$cfg['ServerDefault'] = 0" scenarios, allowing an attacker to bypass the login requirement and execute code without authentication.

Exploitation of CVE-2018-12613 can lead to serious consequences, such as data loss, unauthorized access, and disclosure of sensitive information. An attacker can exploit this vulnerability to execute arbitrary code, modify or delete data, and potentially take over the whole server. Therefore, it is essential to take the necessary precautions to protect digital assets from these types of threats.

Thanks to the pro features of the s4e.io platform, those who read this article can quickly and easily learn about vulnerabilities in their digital assets. The platform provides real-time threat intelligence, vulnerability scanning, and incident management solutions. With s4e.io's advanced security features, users can stay ahead of the latest vulnerabilities and protect their digital assets from attacks. Don't wait until it's too late; take action today to safeguard your online business and personal information with s4e.io.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Always keep software and systems up-to-date, including patches and security updates.
  • Regularly monitor network traffic and system logs for any suspicious activity.
  • Disable unnecessary services and protocols to reduce the attack surface.
  • Implement strong passwords and multi-factor authentication for all users, especially for admin accounts.
  • Use network segmentation to limit access to critical resources and servers.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-12613 scanner - Remote File Inclusion (RFI) vulnerability in phpMyAdmin S4E