Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns parameter of plugins/sql-log.php. An authenticated user can supply path traversal sequences in the ns parameter to write arbitrary .sql files with attacker-controlled content to any writable directory on the host.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 25 Aug 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vrana
Vrana adminer |
|
| Vendors & Products |
Vrana
Vrana adminer |
Tue, 25 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns parameter of plugins/sql-log.php. An authenticated user can supply path traversal sequences in the ns parameter to write arbitrary .sql files with attacker-controlled content to any writable directory on the host. | |
| Title | Adminer sql-log Plugin 5.3.0 through 5.4.2 Arbitrary File Write | |
| First Time appeared |
Adminer
Adminer adminer |
|
| Weaknesses | CWE-73 | |
| CPEs | cpe:2.3:a:adminer:adminer:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Adminer
Adminer adminer |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T01:29:59.097Z
Reserved: 2026-03-31T17:58:43.754Z
Link: CVE-2026-34967
No data.
Status : Received
Published: 2026-08-25T02:16:40.697
Modified: 2026-08-25T02:16:40.697
Link: CVE-2026-34967
No data.
OpenCVE Enrichment
Updated: 2026-08-25T05:30:16Z
Weaknesses