Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-56703

Опубликовано: 25 авг. 2026
Источник: debian

Описание

Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can execute VACUUM INTO to write PHP code to arbitrary file paths and execute commands on the server.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
adminerfixed5.4.3+dfsg-1package

Примечания

  • https://github.com/vrana/adminer/security/advisories/GHSA-gmx3-g29w-77wf

Связанные уязвимости

CVSS3: 7.2
ubuntu
12 дней назад

Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can execute VACUUM INTO to write PHP code to arbitrary file paths and execute commands on the server.

CVSS3: 7.2
nvd
12 дней назад

Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can execute VACUUM INTO to write PHP code to arbitrary file paths and execute commands on the server.

CVSS3: 7.2
github
11 дней назад

Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can execute VACUUM INTO to write PHP code to arbitrary file paths and execute commands on the server.

CVSS3: 7.2
fstec
около 2 месяцев назад

Уязвимость драйвера SQLite программного обеспечения для управления базами данных Adminer, позволяющая нарушителю выполнить произвольный код