Record summary

CVE-2020-26935 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub Advisory4.9.0 to < 4.9.6 · Fixed in 4.9.6affected
5.0.0 to < 5.0.3 · Fixed in 5.0.3affected

Nuclei templates

1
ProjectDiscoveryCRITICALphpMyAdmin < 5.0.3 - SQL InjectionCVSS 9.8

phpMyAdmin before 4.9.6 and 5.x before 5.0.3 contains a SQL injection caused by improper processing of SQL statements in the search feature, letting attackers inject malicious SQL, exploit requires crafted search input.

Impact

Attackers can execute arbitrary SQL commands, potentially leading to data theft, modification, or deletion.

Remediation

Update to phpMyAdmin 4.9.6 or 5.0.3, or latest version.

WeaknessesCWE-89
Authors0x_Akoko
Template tagscvecve2020phpmyadminsqliauthenticated
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Shodan: http.title:"phpMyAdmin"
FOFA: app="phpMyAdmin"

Source: ProjectDiscovery

References

Showing 12 of 15