← Zurück zur CVE-Suche

CVE-2026-56705

Adminer

Beschreibung

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed.

CVSS 9.8EPSS 0.49699999999999994%Risiko 1.02
Quelle öffnen
Veröffentlicht
2026-08-25 02:16:42
Betroffene Versionen
<5.4.3
Typ
Webanwendung
Zuletzt geändert
2026-08-25 16:16:56
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H