Junglewise Threat Intelligence

CVE-2009-1151: phpMyAdmin Remote Code Execution Vulnerability

CVE-2009-1151 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Executive brief

A static code injection vulnerability in setup.php allows remote attackers to inject arbitrary PHP code into a configuration file via the save action. This occurs because the setup script used to generate configurations can be manipulated using crafted POST requests.

Affected products

  • phpMyAdmin phpMyAdmin 2.11.x before 2.11.9.5, 3.x before 3.1.3.1

Timeline

  • 2009-03-24: disclosed: Initial vulnerability discovery/disclosure date based on CVE year and external references.
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-03-25: advisory: NVD publication date.