Sinisterly
Adminer up to 4.6.2 found vulnerable - Printable Version

+- Sinisterly (https://sinister.ly)
+-- Forum: General (https://sinister.ly/Forum-General)
+--- Forum: World News (https://sinister.ly/Forum-World-News)
+--- Thread: Adminer up to 4.6.2 found vulnerable (/Thread-Adminer-up-to-4-6-2-found-vulnerable)



Adminer up to 4.6.2 found vulnerable - sunjester - 01-19-2019

[Image: adminer-wireshark.png]

Quote:AFAIK this attack method has not been published before, but in hindsight I have observed it being used by different Magecart factions at least since October 2018 (although I didn’t understand what was going on back then). The vulnerability was subsequently used to inject payment skimmers on several high-profile stores (government & multinationals).

https://gwillem.gitlab.io/2019/01/17/adminer-4.6.2-file-disclosure-vulnerability/