vrana/adminer via XSS in the history parameter in SQL command
Description
Published by the National Vulnerability Database
Feb 9, 2021
Reviewed
Feb 11, 2021
Published to the GitHub Advisory Database
Feb 11, 2021
Last updated
Sep 21, 2023
Impact
Users of Adminer versions supporting SQL command (most versions, e.g. MySQL) using browsers not encoding URL parameters before sending to server (likely Edge, not Chrome, not Firefox) are affected.
Patches
Patched by 5c395afc, included in version 4.7.9.
Workarounds
Use browser which encodes URL parameters (e.g. Chrome or Firefox).
References
https://sourceforge.net/p/adminer/bugs-and-features/775/
For more information
If you have any questions or comments about this advisory:
References