SOURCEFORGE Adminer是美国SOURCEFORGE社区的一个应用软件。提供单个PHP文件中的数据库管理。 SOURCEFORGE Adminer 中存在代码问题漏洞,该漏洞源于网络系统或产品的代码开发过程中存在设计或实现不当的问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version 4.7.9. | https://github.com/llhala/CVE-2021-21311 | POC Details |
| 2 | None | https://github.com/omoknooni/CVE-2021-21311 | POC Details |
| 3 | Adminer before 4.7.9 is susceptible to server-side request forgery due to exposure of sensitive information in error messages. Users of Adminer versions bundling all drivers, e.g. adminer.php, are affected. An attacker can possibly obtain this information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-21311.yaml | POC Details |
| 4 | None | https://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/Adminer-SSRF%E6%BC%8F%E6%B4%9E%20CVE-2021-21311.md | POC Details |
| 5 | None | https://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/Adminer%20ElasticSearch%20%E5%92%8C%20ClickHouse%20%E9%94%99%E8%AF%AF%E9%A1%B5%E9%9D%A2SSRF%E6%BC%8F%E6%B4%9E%20CVE-2021-21311.md | POC Details |
| 6 | https://github.com/vulhub/vulhub/blob/master/adminer/CVE-2021-21311/README.md | POC Details | |
| 7 | A secure, zero-trust database management tool for WordPress. Fixes critical SSRF vulnerabilities (CVE-2021-21311) by enforcing local connections only. | https://github.com/Sudo-WP/sudowp-adminer | POC Details |
No public POC found.
Login to generate AI POCNo comments yet