Количество 5
Количество 5
CVE-2026-56702
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in _path and execute arbitrary code as the web-server user when uploadPath is web-served.
CVE-2026-56702
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in _path and execute arbitrary code as the web-server user when uploadPath is web-served.
CVE-2026-56702
Adminer versions before 5.4.3 contain an unrestricted file upload vuln ...
GHSA-p84v-vg3f-p9m6
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in _path and execute arbitrary code as the web-server user when uploadPath is web-served.
BDU:2026-12786
Уязвимость плагина AdminerFileUpload модуля plugins/file-upload.php программного обеспечения для управления базами данных Adminer, позволяющая нарушителю выполнить произвольный код
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-56702 Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in _path and execute arbitrary code as the web-server user when uploadPath is web-served. | CVSS3: 8.8 | 0% Низкий | 12 дней назад | |
CVE-2026-56702 Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in _path and execute arbitrary code as the web-server user when uploadPath is web-served. | CVSS3: 8.8 | 0% Низкий | 12 дней назад | |
CVE-2026-56702 Adminer versions before 5.4.3 contain an unrestricted file upload vuln ... | CVSS3: 8.8 | 0% Низкий | 12 дней назад | |
GHSA-p84v-vg3f-p9m6 Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in _path and execute arbitrary code as the web-server user when uploadPath is web-served. | CVSS3: 8.8 | 0% Низкий | 12 дней назад | |
BDU:2026-12786 Уязвимость плагина AdminerFileUpload модуля plugins/file-upload.php программного обеспечения для управления базами данных Adminer, позволяющая нарушителю выполнить произвольный код | CVSS3: 8.8 | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу