Description phpMyAdmin是phpMyAdmin团队开发的一套免费的、基于Web的MySQL数据库管理工具。该工具能够创建和删除数据库,创建、删除、修改数据库表,执行SQL脚本命令等。
References https://github.com/ADummmy/vulhub_Writeup/blob/main/PhpMyAdmin_RCE.md https://www.cnblogs.com/lthlsy/p/14773290.html https://blog.csdn.net/qq_41832837/article/details/110100845 https://github.com/vulhub/vulhub/blob/master/phpmyadmin/CVE-2016-5734/README.zh-cn.md https://shawroot.hatenablog.com/entry/2020/01/08/phpMyAdmin_4.0.x%E2%80%944.6.2_%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%EF%BC%88CVE-2016-5734%EF%BC%89 https://blog.csdn.net/haoxue__/article/details/129349436 https://developer.aliyun.com/article/1099633 https://www.exploit-db.com/exploits/40185 https://nvd.nist.gov/vuln/detail/CVE-2016-5734 https://github.com/vulhub/vulhub/blob/master/phpmyadmin/CVE-2016-5734/README.md https://www.phpmyadmin.net/security/PMASA-2016-27/
Related VulnerabilitiesPoCCVE-2026-0692: BlueSnap Payment Gateway for WooCommerce <=3.4.0 - IPN Authorization BypassPoCCVE-2026-26216: Crawl4AI < 0.8.0 - Unauthenticated Remote Code Execution via Hooks ParameterPoCCVE-2026-40281: Gotenberg <= 8.30.1 - Remote Code ExecutionPoCCVE-2026-49468: LiteLLM Proxy < 1.84.0 - Host Header Authentication BypassPoCCVE-2026-86242: Bifrost < 1.6.3 - Unauthenticated Remote Plugin URL FetchPoCCVE-2024-57728: SimpleHelp <= 5.5.7 - Arbitrary File UploadPoCCVE-2025-11452: Asgaros Forum < 3.2.0 - SQL InjectionPoCCVE-2025-34033: Blue Angel Software Suite (5V Technologies) - OS Command InjectionPoCCVE-2026-12227: Visual Composer <= 45.16.0 - Unauthenticated LFIPoCCVE-2026-56681: 9router <=0.5.4 - Authentication BypassPoCCVE-2026-89013: Dolibarr < 24.0.0 - Authorization Bypass via hashp ParameterPoCCVE-2026-49060: Hippoo Mobile App for WooCommerce - Broken Access ControlPoCCVE-2026-58467: Cockpit CMS <= 2.14.0 - Path Traversal / Local File Inclusion