Description phpMyAdmin是phpMyAdmin团队开发的一套免费的、基于Web的MySQL数据库管理工具。该工具能够创建和删除数据库,创建、删除、修改数据库表,执行SQL脚本命令等。
References https://github.com/ADummmy/vulhub_Writeup/blob/main/PhpMyAdmin_RCE.md https://www.cnblogs.com/lthlsy/p/14773290.html https://blog.csdn.net/qq_41832837/article/details/110100845 https://github.com/vulhub/vulhub/blob/master/phpmyadmin/CVE-2016-5734/README.zh-cn.md https://shawroot.hatenablog.com/entry/2020/01/08/phpMyAdmin_4.0.x%E2%80%944.6.2_%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%EF%BC%88CVE-2016-5734%EF%BC%89 https://blog.csdn.net/haoxue__/article/details/129349436 https://developer.aliyun.com/article/1099633 https://www.exploit-db.com/exploits/40185 https://nvd.nist.gov/vuln/detail/CVE-2016-5734 https://github.com/vulhub/vulhub/blob/master/phpmyadmin/CVE-2016-5734/README.md https://www.phpmyadmin.net/security/PMASA-2016-27/
Related VulnerabilitiesPoCCVE-2020-29134: TOTVS Fluig <= 1.7.0 - Arbitrary File ReadPoCCVE-2023-54391: Proxmox VE - Default Credentials with TFA BypassPoCCVE-2026-0702: VidShop for WooCommerce <= 1.1.4 - SQL InjectionPoCCVE-2026-19092: Tutor LMS < 4.0.6 - Unauthenticated Arbitrary PHP Function InvocationPoCCVE-2026-27454: Discourse <=2026.2.0 - Hidden Post Revision Disclosure via revert_to Authorization BypassPoCCVE-2026-28141: NextGEN Gallery <= 4.2.3 - Reflected Cross-Site ScriptingPoCCVE-2026-28411: WeGIA < 3.6.5 - Unauthenticated Authentication Bypass via extract()PoCCVE-2026-30849: MantisBT < 2.28.1 - SOAP API Authentication BypassPoCCVE-2026-34234: CtrlPanel <= 1.1.1 - Remote Code ExecutionPoCCVE-2026-41452: Krayin CRM < 2.2.1 - Installer Authentication BypassPoCCVE-2026-41456: Bludit CMS <= 3.20.0 - Cross-Site ScriptingPoCCVE-2026-41679: Paperclip - Remote Code ExecutionPoCCVE-2026-41948: Dify <=1.14.1 - Unauthenticated Plugin Daemon Path Traversal