Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-56703

Опубликовано: 25 авг. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 7.2

Описание

Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can execute VACUUM INTO to write PHP code to arbitrary file paths and execute commands on the server.

РелизСтатусПримечание
devel

not-affected

6.0.0-1
esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

jammy

needs-triage

noble

needs-triage

resolute

needs-triage

Показывать по

7.2 High

CVSS3

Связанные уязвимости

CVSS3: 7.2
nvd
12 дней назад

Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can execute VACUUM INTO to write PHP code to arbitrary file paths and execute commands on the server.

CVSS3: 7.2
debian
12 дней назад

Adminer before 5.4.3 contains a remote code execution vulnerability in ...

CVSS3: 7.2
github
11 дней назад

Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can execute VACUUM INTO to write PHP code to arbitrary file paths and execute commands on the server.

CVSS3: 7.2
fstec
около 2 месяцев назад

Уязвимость драйвера SQLite программного обеспечения для управления базами данных Adminer, позволяющая нарушителю выполнить произвольный код

7.2 High

CVSS3