Adminer 在 5.4.3 版本之前存在任意文件删除漏洞。在 SQLite 模式下,当执行数据库列表的删除操作时,系统未对文件扩展名进行验证。已认证的攻击者可以通过在 db[] 参数中提交任意相对文件路径,删除 PHP 进程具有写权限的任何文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-56705 | 9.8 CRITICAL | Adminer before 5.4.3 Remote Code Execution via MSSQL PDO DSN Injection |
| CVE-2026-56702 | 8.8 HIGH | Adminer before 5.4.3 Unrestricted File Upload via AdminerFileUpload |
| CVE-2026-56703 | 7.2 HIGH | Adminer before 5.4.3 Remote Code Execution via SQLite VACUUM INTO |
| CVE-2026-56706 | 6.8 MEDIUM | Adminer before 5.4.3 CSRF Token Secret Recovery via XOR Masking |
| CVE-2026-56704 | 6.1 MEDIUM | Adminer before 5.4.3 Cross-Site Scripting via MySQL Version String |
| CVE-2026-34964 | 5.8 MEDIUM | Adminer before 5.5.0 SSRF via PDO DSN Injection |
| CVE-2026-34967 | 5.4 MEDIUM | Adminer sql-log Plugin 5.3.0 through 5.4.2 Arbitrary File Write |
| CVE-2026-34959 | 4.7 MEDIUM | Adminer before 5.5.0 Open Redirect via X-Forwarded-Prefix |
| CVE-2026-16434 | 2.3 LOW | Adminer before 5.5.1 X-Forwarded-Prefix Backslash Bypass |
No comments yet