Adminer up to 4.6.2 found vulnerable 01-19-2019, 09:58 AM
#1
![[Image: adminer-wireshark.png]](https://gwillem.gitlab.io/assets/img/adminer-wireshark.png)
Quote:AFAIK this attack method has not been published before, but in hindsight I have observed it being used by different Magecart factions at least since October 2018 (although I didn’t understand what was going on back then). The vulnerability was subsequently used to inject payment skimmers on several high-profile stores (government & multinationals).
https://gwillem.gitlab.io/2019/01/17/adm...erability/


![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)