Executive brief
A static code injection vulnerability in setup.php allows remote attackers to inject arbitrary PHP code into a configuration file via the save action. This occurs because the setup script used to generate configurations can be manipulated using crafted POST requests.
Affected products
- phpMyAdmin phpMyAdmin 2.11.x before 2.11.9.5, 3.x before 3.1.3.1
Timeline
- 2009-03-24: disclosed: Initial vulnerability discovery/disclosure date based on CVE year and external references.
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-03-25: advisory: NVD publication date.