Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2580-1
It was discovered that there was a server-side request forgery exploit in adminer, a web-based database administration tool. Adminer allowed unauthenticated connections to be initiated to arbitrary . Package : adminer Version : 3.3.3-1+deb7u1 CVE ID : CVE-2018-7667 Debian Bug : #893668 It was discovered that there was a server-side request forgery exploit in adminer, a web-based database administration tool. Adminer allowed unauthenticated connections to be initiated to arbitrary systems and ports which could bypass external firewalls to identify internal hosts or perform port scanning of other servers. For Debian 7 "Wheezy", this issue has been fixed in adminer version 3.3.3-1+deb7u1. We recommend that you upgrade your adminer packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
Get the latest Linux and open source security news straight to your inbox.