Skip to content
← All posts

Tagged

Security

18 posts

From The Wire

Adminer patches an RCE hiding behind a UTF-8 byte-order mark

A regex filter meant to block dangerous SQLite commands in Adminer missed statements prefixed with a UTF-8 BOM, letting an authenticated user write PHP straight to a web-accessible directory. Fixed in 6.1.1.

via GitHub Security Advisories (vrana/adminer)