Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-49h4-j9cq-22wg

Опубликовано: 25 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 5.4

Описание

Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns parameter of plugins/sql-log.php. An authenticated user can supply path traversal sequences in the ns parameter to write arbitrary .sql files with attacker-controlled content to any writable directory on the host.

Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns parameter of plugins/sql-log.php. An authenticated user can supply path traversal sequences in the ns parameter to write arbitrary .sql files with attacker-controlled content to any writable directory on the host.

EPSS

Процентиль: 15%
0.00237
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-73

Связанные уязвимости

CVSS3: 5.4
ubuntu
20 дней назад

Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns parameter of plugins/sql-log.php. An authenticated user can supply path traversal sequences in the ns parameter to write arbitrary .sql files with attacker-controlled content to any writable directory on the host.

CVSS3: 5.4
nvd
20 дней назад

Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns parameter of plugins/sql-log.php. An authenticated user can supply path traversal sequences in the ns parameter to write arbitrary .sql files with attacker-controlled content to any writable directory on the host.

CVSS3: 5.4
debian
20 дней назад

Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled c ...

EPSS

Процентиль: 15%
0.00237
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-73