Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version 4.7.9.
We have discovered 161 live websites that are affected by CVE-2021-21311.
| Product | |
| Category | Database Managers |
| Vulnerable Domains | 161 live websites (34% of Adminer install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 12 versions ( 33% of all versions) |
| 24 websites | |
| 74 websites | |
| 28 websites | |
| 7 websites | |
| 6 websites | |
| 4 websites | |
| 3 websites | |
| 3 websites | |
| 2 websites | |
| 2 websites |
| .cz | 70 websites |
| .com | 24 websites |
| .eu | 7 websites |
| .nl | 6 websites |
| .ch | 5 websites |
| .de | 4 websites |
| .net | 4 websites |
| .ru | 3 websites |
| .org | 3 websites |
| .it | 2 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****************.**.********.com | *,***,*** | ||
| *********.********.com | *,***,*** | ||
| ***********************.**.********.com | *,***,*** | ||
| ****.*********.cz | *,***,*** | ||
| *********.*******.pro | *,***,*** | ||
| ***.*******.pro | *,***,*** | ||
| ****.********.cz | *,***,*** | ||
| *****.********.ch | *,***,*** | ||
| ****.*******.pro | *,***,*** | ||
| *********.*******.pro | *,***,*** |
FAQ