跳转到帖子

recommended_posts

发布于
  • Members

pgAdmin Binary Path API RCE

Disclosed
03/28/2024
Created
08/28/2024

Description

pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data. Tested on pgAdmin 8.4 on Windows 10 both authenticated and unauthenticated.

Author(s)

  • M.Selim Karahan
  • Mustafa Mutlu
  • Ayoub Mokhtar

Platform

Windows

Architectures

x64

Development

  • Source Code
  • History
  • 查看数 703
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…