CVE-2023-45197

Adminer and AdminerEvo vulnerable to directory traversal and file upload

The file upload plugin in Adminer and AdminerEvo allows an attacker to upload a file with a table name of “..” to the root of the Adminer directory. The attacker can effectively guess the name of the uploaded file and execute it. Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.3.


We have discovered 391 live websites that are affected by CVE-2023-45197.

Run a Free Instant Scan




Affected Software

Product  Adminer
Category Database Managers
Vulnerable Domains391 live websites (82% of Adminer install base)
Vulnerable Versions
  • from 0 through 4.8.3
Vulnerable Versions Count24 versions ( 67% of all versions)


Common Weakness Enumeration

CWE-434 Unrestricted Upload of File with Dangerous Type



Details

  • Published - Jun 21, 2024
  • Updated - Aug 2, 2024

Website Distribution by Country

Number of websites using CVE-2023-45197
United States116 websites



Czech Republic92 websites
Germany59 websites
France20 websites
Russia17 websites
Netherlands10 websites
Singapore10 websites
China8 websites
Slovakia7 websites
Lithuania6 websites

Website Distribution by TLD

Number of websites using CVE-2023-45197
.com137 websites
.cz86 websites
.ru17 websites
.net16 websites
.org14 websites
.de13 websites
.eu10 websites
.nl7 websites
.io6 websites
.fr6 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-45197

Top websites that are affected by CVE-2023-45197. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.********.com Czech Republic**,***
******.***.pl Poland***,***
*******.pl Poland***,***
****.*****.com United States***,***
*********.com Germany***,***
**************.ru Russia***,***
***.*********.com United States***,***
***********.************.com United States***,***
******.*************.cz Czech Republic***,***
*******.***.cn China***,***
See full domain list

FAQ

CVE-2023-45197 is Unrestricted Upload of File with Dangerous Type in Adminer
A total of 391 websites have been identified as vulnerable to CVE-2023-45197, based on global website indexing conducted by WebTechSurvey.
The Adminer is affected by the CVE-2023-45197 vulnerability.
Adminer versions up to and including 4.8.3 are vulnerable to CVE-2023-45197.