PT-2026-3806 · Unknown · Phppgadmin

Valerio Severini

·

Publicado

2020-11-07

·

Atualizado

2026-01-23

·

CVE-2021-47853

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions phpPgAdmin version 7.13.0
Description An authenticated attacker can execute arbitrary system commands through SQL query manipulation. This is achieved by creating a custom table, uploading a malicious .txt file, and utilizing the COPY FROM PROGRAM command to execute operating system commands with the application's privileges.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the COPY FROM PROGRAM command. Avoid using SQL queries that involve file uploads or external program execution.

Exploit

Correção

RCE

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-00981
CVE-2021-47853
GHSA-86GH-C8R8-XWHQ

Produtos afetados

Phppgadmin