CVE-2020-26935
CRITICAL NUCLEIphpMyAdmin <4.9.6, <5.0.3 - SQL Injection
Title source: llmDescription
An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.
Nuclei Templates (1)
phpMyAdmin < 5.0.3 - SQL Injection
CRITICALVERIFIEDby 0x_Akoko
Shodan:
http.title:"phpMyAdmin"
FOFA:
app="phpMyAdmin"
References (9)
Scores
CVSS v3
9.8
EPSS
0.9152
EPSS Percentile
99.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (9)
debian/debian_linux
9.0
fedoraproject/fedora
31
fedoraproject/fedora
32
fedoraproject/fedora
33
opensuse/backports_sle
15.0 (3 CPE variants)
opensuse/leap
15.1
opensuse/leap
15.2
phpmyadmin/phpmyadmin
4.9.0 - 4.9.6
phpmyadmin/phpmyadmin
4.9.0 - 4.9.6Packagist
Published
Oct 10, 2020
Tracked Since
Feb 18, 2026