CVE-2026-34967

Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns parameter of plugins/sql-log.php. An authenticated user can supply path traversal sequences in the ns parameter to write arbitrary .sql files with attacker-controlled content to any writable directory on the host.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-25 02:16

Updated : 2026-09-08 20:23


NVD link : CVE-2026-34967

Mitre link : CVE-2026-34967

CVE.ORG link : CVE-2026-34967


JSON object : View

Products Affected

No product.

CWE
CWE-73

External Control of File Name or Path