在 Adminer 5.4.3 之前版本中,AdminerFileUpload 插件存在一个不受限制的文件上传漏洞。攻击者可以通过利用宽松的默认扩展名允许列表,以认证用户身份上传 PHP 文件。如果 uploadPath 指向可被 Web 访问的目录,攻击者可以将 PHP WebShell 上传至以 结尾的字段列中,并以 Web 服务器用户的权限执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-56705 | 9.8 CRITICAL | Adminer before 5.4.3 Remote Code Execution via MSSQL PDO DSN Injection |
| CVE-2026-34968 | 8.1 HIGH | Adminer before 5.4.3 Arbitrary File Deletion via SQLite Drop |
| CVE-2026-56703 | 7.2 HIGH | Adminer before 5.4.3 Remote Code Execution via SQLite VACUUM INTO |
| CVE-2026-56706 | 6.8 MEDIUM | Adminer before 5.4.3 CSRF Token Secret Recovery via XOR Masking |
| CVE-2026-56704 | 6.1 MEDIUM | Adminer before 5.4.3 Cross-Site Scripting via MySQL Version String |
| CVE-2026-34964 | 5.8 MEDIUM | Adminer before 5.5.0 SSRF via PDO DSN Injection |
| CVE-2026-34967 | 5.4 MEDIUM | Adminer sql-log Plugin 5.3.0 through 5.4.2 Arbitrary File Write |
| CVE-2026-34959 | 4.7 MEDIUM | Adminer before 5.5.0 Open Redirect via X-Forwarded-Prefix |
| CVE-2026-16434 | 2.3 LOW | Adminer before 5.5.1 X-Forwarded-Prefix Backslash Bypass |
No comments yet