Количество 5
Количество 5
CVE-2026-56705
Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed.
CVE-2026-56705
Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed.
CVE-2026-56705
Adminer before 5.4.3 fails to sanitize the server field before constru ...
GHSA-34q8-53jm-qc2r
Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed.
BDU:2026-12785
Уязвимость программного обеспечения для управления базами данных Adminer, связанная с некорректным внешним управлением именем или путем файла, позволяющая нарушителю выполнить произвольный код
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-56705 Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed. | CVSS3: 9.8 | 0% Низкий | 12 дней назад | |
CVE-2026-56705 Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed. | CVSS3: 9.8 | 0% Низкий | 12 дней назад | |
CVE-2026-56705 Adminer before 5.4.3 fails to sanitize the server field before constru ... | CVSS3: 9.8 | 0% Низкий | 12 дней назад | |
GHSA-34q8-53jm-qc2r Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed. | CVSS3: 9.8 | 0% Низкий | 12 дней назад | |
BDU:2026-12785 Уязвимость программного обеспечения для управления базами данных Adminer, связанная с некорректным внешним управлением именем или путем файла, позволяющая нарушителю выполнить произвольный код | CVSS3: 9.8 | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу