CVE-2020-26935
CRITICAL NUCLEIphpMyAdmin <4.9.6, <5.0.3 - SQL Injection
Title source: llmDescription
An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.
Nuclei Templates (1)
phpMyAdmin < 5.0.3 - SQL Injection
CRITICALVERIFIEDby 0x_Akoko
Shodan:
http.title:"phpMyAdmin"
FOFA:
app="phpMyAdmin"
References (9)
Scores
CVSS v3
9.8
EPSS
0.9201
EPSS Percentile
99.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-89
Status
published
Affected Products (11)
phpmyadmin/phpmyadmin
< 4.9.6
opensuse/backports_sle
opensuse/backports_sle
opensuse/backports_sle
opensuse/leap
opensuse/leap
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
debian/debian_linux
phpmyadmin/phpmyadmin
< 4.9.6Packagist
Timeline
Published
Oct 10, 2020
Tracked Since
Feb 18, 2026