🛡️ CVE Monitor
Dịch vụ / phần mềm liên quan: MySQL / MariaDB

Mô tả

Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function in adminer/include/functions.inc.php. The port capture group requires pure digits anchored to the end of the string, so any server value with a non-digit tail fails the regex and falls back to returning the whole string as the host with an empty port. Because the privileged-port restriction in adminer/include/auth.inc.php inspects only the parsed port, the check is skipped, and the mysqli/mysqlnd client subsequently re-parses host:port from the host string and opens a TCP connection. A remote, unauthenticated attacker who can reach the Adminer login page can submit a crafted value such as 127.0.0.1:80/x to make the server initiate TCP connections to arbitrary internal hosts and privileged ports before credentials are validated, enabling server-side request forgery and blind internal port scanning (connection refused vs. handshake vs. timeout acts as a liveness oracle). This is a regression that re-opens the bypass fixed in 5.5.0 (GHSA-58cq-mgw2-38m5). Fixed in 6.0.2.

Chi tiết

Trạng tháiAwaiting Analysis
Điểm CVSS5.8 (v3.1)
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Ngày công bố21:16 26/09/2026
Ngày cập nhật23:37 28/09/2026
Nguồn dữ liệunvd

CWE

  • CWE-918

Sản phẩm bị ảnh hưởng

Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.

Tài liệu tham khảo

Lịch sử thay đổi

Thời gianLoạiTrườngGiá trị cũGiá trị mới
23:37 28/09/2026 CREATED cve MEDIUM

Tất cả thời gian trên trang này hiển thị theo giờ Việt Nam (GMT+7).