A vulnerability in the search feature allowed malicious users to inject SQL by crafting database or table names.
Marco hated late-night calls.
Hundreds of times. Over the last week.
Retrieve sensitive contents from other databases on the same server. phpmyadmin 4.9.5 exploit