Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-56705

Опубликовано: 25 авг. 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed.

EPSS

Процентиль: 41%
0.00497
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-73

Связанные уязвимости

CVSS3: 9.8
ubuntu
12 дней назад

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed.

CVSS3: 9.8
debian
12 дней назад

Adminer before 5.4.3 fails to sanitize the server field before constru ...

CVSS3: 9.8
github
11 дней назад

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed.

CVSS3: 9.8
fstec
около 2 месяцев назад

Уязвимость программного обеспечения для управления базами данных Adminer, связанная с некорректным внешним управлением именем или путем файла, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 41%
0.00497
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-73