Описание
Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. adminer.php) are affected. This is fixed in version 4.7.9.
Ссылки
- Patch
- ExploitThird Party Advisory
- PatchThird Party Advisory
- Mailing ListThird Party Advisory
- ProductThird Party Advisory
- Patch
- ExploitThird Party Advisory
- PatchThird Party Advisory
- Mailing ListThird Party Advisory
- ProductThird Party Advisory
- US Government Resource
Уязвимые конфигурации
EPSS
7.2 High
CVSS3
6.4 Medium
CVSS2
Дефекты
Связанные уязвимости
Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version 4.7.9.
Adminer is an open-source database management in a single PHP file. In ...
Уязвимость программного обеспечения для управления базами данных Adminer, связанная с недостаточной проверкой запросов на стороне сервера, позволяющая нарушителю осуществить SSRF-атаку
EPSS
7.2 High
CVSS3
6.4 Medium
CVSS2