Vendor
critical
advisory
Remote Code Execution in Adminer via PDO DSN Injection
3 rules 2 TTPs 4 CVEsAdminer versions prior to 5.4.3 are vulnerable to unauthenticated remote code execution via DSN injection, allowing attackers to write arbitrary PHP files to the web root.
PoC
Adminer +1
web-vulnerability
rce
cve-2026-56705
vulnerability
web-application
cve-2026-34968
3r
2t
4c
updated
high
advisory
Adminer Cookie Injection Vulnerability via X-Forwarded-Prefix Header (CVE-2026-63771)
1 rule 1 TTP 1 CVEAdminer versions prior to 5.4.3 are vulnerable to a cookie injection flaw, which allows attackers to manipulate cookie attributes by injecting arbitrary values through the unsanitized X-Forwarded-Prefix HTTP header, enabling cross-origin authenticated requests and bypassing cookie security controls.
Adminer < 5.4.3
web-vulnerability
cookie-injection
cve
CWE-113
1r
1t
1c