Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j4fh-9p52-f987

Опубликовано: 25 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 7.2

Описание

Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can execute VACUUM INTO to write PHP code to arbitrary file paths and execute commands on the server.

Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can execute VACUUM INTO to write PHP code to arbitrary file paths and execute commands on the server.

EPSS

Процентиль: 64%
0.01134
Низкий

8.6 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.2
ubuntu
10 дней назад

(Adminer before 5.4.3 contains a remote code execution vulnerability in ...)

CVSS3: 7.2
nvd
12 дней назад

Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can execute VACUUM INTO to write PHP code to arbitrary file paths and execute commands on the server.

CVSS3: 7.2
debian
12 дней назад

Adminer before 5.4.3 contains a remote code execution vulnerability in ...

CVSS3: 7.2
fstec
около 2 месяцев назад

Уязвимость драйвера SQLite программного обеспечения для управления базами данных Adminer, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 64%
0.01134
Низкий

8.6 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-94