![]() |
|
Adminer up to 4.6.2 found vulnerable - Printable Version +- Sinisterly (https://sinister.ly) +-- Forum: General (https://sinister.ly/Forum-General) +--- Forum: World News (https://sinister.ly/Forum-World-News) +--- Thread: Adminer up to 4.6.2 found vulnerable (/Thread-Adminer-up-to-4-6-2-found-vulnerable) |
Adminer up to 4.6.2 found vulnerable - sunjester - 01-19-2019 ![]() Quote:AFAIK this attack method has not been published before, but in hindsight I have observed it being used by different Magecart factions at least since October 2018 (although I didn’t understand what was going on back then). The vulnerability was subsequently used to inject payment skimmers on several high-profile stores (government & multinationals). https://gwillem.gitlab.io/2019/01/17/adminer-4.6.2-file-disclosure-vulnerability/ |