Description

Adminer is a tool for managing content in MySQL databases. Adminer is distributed under Apache license in a form of a single PHP file.

Adminer versions up to (and including) 4.6.2 supported the use of the SQL statement LOAD DATA INFILE. It was possible to use this SQL statement to read arbitrary local files because of a protocol flaw in MySQL.

Remediation

Upgrade to the latest version of Adminer. This vulnerability was fixed in Adminer version 4.6.3.

References

Related Vulnerabilities