Vulnerability Description
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpmyadmin | Phpmyadmin | >= 2.11.0, < 2.11.9.5 |
| Debian | Debian Linux | 4.0 |
Related Weaknesses (CWE)
References
- http://labs.neohapsis.com/2009/04/06/about-cve-2009-1151/Broken Link
- http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.htmlProduct
- http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/branches/MAINT_2_11_9/phVendor Advisory
- http://secunia.com/advisories/34430Broken LinkVendor Advisory
- http://secunia.com/advisories/34642Broken LinkVendor Advisory
- http://secunia.com/advisories/35585Broken LinkVendor Advisory
- http://secunia.com/advisories/35635Broken LinkVendor Advisory
- http://security.gentoo.org/glsa/glsa-200906-03.xmlThird Party Advisory
- http://www.debian.org/security/2009/dsa-1824Mailing List
- http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-prExploitIssue Tracking
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:115Broken Link
- http://www.phpmyadmin.net/home_page/security/PMASA-2009-3.phpPatchVendor Advisory
- http://www.securityfocus.com/archive/1/504191/100/0/threadedBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/34236Broken LinkThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/8921ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2009-1151?
CVE-2009-1151 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save...
How severe is CVE-2009-1151?
CVE-2009-1151 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2009-1151?
Check the references section above for vendor advisories and patch information. Affected products include: Phpmyadmin Phpmyadmin, Debian Debian Linux.