Adminer versions 1.12.0 to 4.6.2 suffer from improper access control, allowing an attacker to achieve arbitrary file read on the remote server. The vulnerability is triggered when Adminer is instructed to connect to a remote MySQL database, which can be abused to read files from the server's filesystem.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept exploit for CVE-2021-43008, a file disclosure vulnerability in Adminer <= 4.6.2. The exploit consists of a rogue MySQL server implemented in Python (rogue_mysql_server/rogue_mysql_server.py), which, when connected to by a vulnerable Adminer instance, abuses the MySQL protocol to request arbitrary files from the Adminer server using the LOAD DATA LOCAL INFILE command. The exploit is orchestrated using Docker Compose, which sets up three services: a vulnerable Adminer instance, a legitimate MySQL server, and the rogue MySQL server. The main exploit logic is in the Python script, which listens on TCP port 33306 and, upon connection, requests files such as /etc/passwd from Adminer. When Adminer responds with the file contents, the rogue server saves them locally. The repository also includes documentation (README.md) explaining the vulnerability, exploitation steps, and mitigation strategies. No detection scripts or fake exploits are present; the code is a functional PoC for the described vulnerability.
This repository contains a proof-of-concept exploit targeting Adminer (a web-based database management tool) in conjunction with a MySQL/MariaDB server. The exploit consists of a Python script (exploit.py) and a Bash setup script (script.sh). The Bash script configures the MySQL server to allow remote connections, enables the 'local_infile' option, and creates a user with full privileges. The Python script then logs into Adminer using the configured credentials and issues SQL queries to read arbitrary files from the server (such as /flag.txt) using the LOAD DATA LOCAL INFILE command, storing the results in a database table that can be read back via Adminer. The exploit demonstrates the risk of misconfigured Adminer and MySQL/MariaDB servers, particularly when 'local_infile' is enabled and Adminer is exposed to untrusted users. The README simply instructs to start the setup script. No hardcoded CVE is referenced, but the technique is a known class of file read vulnerabilities in database management interfaces.
This repository provides an operational Python exploit (AdminerRead.py) for CVE-2021-43008, targeting Adminer versions 1.0 through 4.6.2. The exploit abuses an arbitrary file read vulnerability in the Adminer web interface, allowing an attacker with network access and valid database credentials to retrieve files from the server's filesystem. The main script, AdminerRead.py, automates the exploitation process, including authentication, file enumeration, and file retrieval. The repository includes wordlists of common sensitive files (e.g., /etc/passwd, /etc/shadow, SSH keys, web server configs) to facilitate automated file discovery. Supporting files include documentation, Dockerfiles for testing, and Makefiles for environment setup. The exploit is not part of a framework and is a standalone operational tool.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.