Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-34q8-53jm-qc2r

Опубликовано: 25 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed.

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed.

EPSS

Процентиль: 41%
0.00497
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-73

Связанные уязвимости

CVSS3: 9.8
ubuntu
12 дней назад

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed.

CVSS3: 9.8
nvd
12 дней назад

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed.

CVSS3: 9.8
debian
12 дней назад

Adminer before 5.4.3 fails to sanitize the server field before constru ...

CVSS3: 9.8
fstec
около 2 месяцев назад

Уязвимость программного обеспечения для управления базами данных Adminer, связанная с некорректным внешним управлением именем или путем файла, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 41%
0.00497
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-73