PHPMyAdmin SearchController SQL Injection

Strike ID:
E21-a4zb1
CVSS:
9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
False Positive:
t
Variants:
1
Year:
2020

Description

This strike exploits an sql injection vulnerability in phpMyAdmin. The vulnerability is due to a lack of escaping or input validation on the user-supplied input. A remote, authenticated attacker can exploit this vulnerability by sending crafted requests to the target server. Successful exploitation could result in the execution of arbitrary SQL statement, potentially leading to the disclosure of sensitive information.

CVE

References