Remote command execution In phppgadmin/phppgadmin
Description
phpPgAdmin contains a remote command execution vulnerability phpPgAdmin 7.13.0 contains a remote command execution vulnerability that allows authenticated attackers to execute arbitrary system commands through SQL query manipulation. Attackers can create a custom table, upload a malicious .txt file, and use the COPY FROM PROGRAM command to execute operating system commands with the application's privileges.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version |
|---|---|---|
packagist |
Aliases
1. 2. 3. 4.
References
1. 2. 3.