PT-2009-1127 · Phpmyadmin · Phpmyadmin

Greg Ose

·

Published

2009-03-24

·

Updated

2025-10-22

·

CVE-2009-1151

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions phpMyAdmin versions 2.11.x through 2.11.9.4 phpMyAdmin versions 3.x through 3.1.3.0
Description The issue is related to a static code injection vulnerability in the setup.php file of phpMyAdmin. This vulnerability allows remote attackers to inject arbitrary PHP code into a configuration file via the save action. The exploitation of this vulnerability can enable a remote attacker to execute arbitrary PHP code.
Recommendations For phpMyAdmin versions 2.11.x through 2.11.9.4, update to version 2.11.9.5 or later. For phpMyAdmin versions 3.x through 3.1.3.0, update to version 3.1.3.1 or later.

Exploit

Fix

Improper Encoding or Escaping of Output

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2025-00175
CVE-2009-1151
DSA-1824-1

Affected Products

Phpmyadmin