Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-56705

Опубликовано: 25 авг. 2026
Источник: debian
EPSS Низкий

Описание

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
adminerfixed5.4.3+dfsg-1package

Примечания

  • https://github.com/vrana/adminer/security/advisories/GHSA-r4x9-5m63-3vxw

EPSS

Процентиль: 41%
0.00497
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
12 дней назад

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed.

CVSS3: 9.8
nvd
12 дней назад

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed.

CVSS3: 9.8
github
11 дней назад

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed.

CVSS3: 9.8
fstec
около 2 месяцев назад

Уязвимость программного обеспечения для управления базами данных Adminer, связанная с некорректным внешним управлением именем или путем файла, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 41%
0.00497
Низкий