CVE-2009-1151

CRITICAL KEV NUCLEI

phpMyAdmin 2.11.0-2.11.9.4 and 3.x < 3.1.3.1 - Remote Code Injection via Setup Configuration Save

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2009-1151 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 25, 2022. EIP tracks 7 public exploits from researchers including Metasploit, Hacking Expose!, Adrian _pagvac_ Pastor, including a Metasploit module exploits/unix/webapp/phpmyadmin_config. A Nuclei detection template is also available.

AI-analyzed exploit summary This Metasploit module exploits a code injection vulnerability in phpMyAdmin's setup feature, allowing arbitrary PHP code execution by injecting payloads into the configuration file. It targets versions 2.11.x < 2.11.9.5 and 3.x < 3.1.3.1.

Description

Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.

Exploits (7)

exploitdb WORKING POC VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/16913

This Metasploit module exploits a code injection vulnerability in phpMyAdmin's setup feature, allowing arbitrary PHP code execution by injecting payloads into the configuration file. It targets versions 2.11.x < 2.11.9.5 and 3.x < 3.1.3.1.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: phpMyAdmin 2.11.x < 2.11.9.5 and 3.x < 3.1.3.1
No auth needed
Prerequisites: Access to the phpMyAdmin setup script · Network connectivity to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb SCANNER VERIFIED
by Hacking Expose! · phpwebappsphp
https://www.exploit-db.com/exploits/8992

This script scans for phpMyAdmin installations using Google dorks and checks for potential vulnerabilities, including CVE-2009-1151. It does not contain a full exploit but identifies targets for further exploitation.

Classification
Scanner 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: phpMyAdmin (multiple versions)
No auth needed
Prerequisites: Google search access · Internet connectivity
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Adrian _pagvac_ Pastor · bashwebappsphp
https://www.exploit-db.com/exploits/8921

This exploit leverages a PHP code injection vulnerability in phpMyAdmin's setup.php script to achieve remote code execution (RCE). It injects malicious PHP code into the configuration file, allowing arbitrary command execution via HTTP GET parameters.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1
No auth needed
Prerequisites: Vulnerable phpMyAdmin version · Presence of /config/ directory · Wizard-based installation of phpMyAdmin
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 6 stars
by pagvac · remote
https://github.com/pagvac/pocs

This repository contains a functional exploit for CVE-2009-1151, a PHP code injection vulnerability in phpMyAdmin's setup script. The exploit injects malicious PHP code into the configuration file, enabling remote command execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: phpMyAdmin versions 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1
No auth needed
Prerequisites: Vulnerable phpMyAdmin version · Presence of the '/config/' directory · Installation via wizard method
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec STUB
by tpdlshdmlrkfmcla · poc
https://github.com/tpdlshdmlrkfmcla/ZmEu

The repository contains only a minimal README with a CVE reference and no functional exploit code or technical details. It appears to be a placeholder or stub.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: phpMyAdmin
No auth needed
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by e-Thug · remote
https://github.com/e-Thug/PhpMyAdmin

This repository contains a Python script that exploits CVE-2009-1151, a vulnerability in phpMyAdmin's setup script allowing remote code execution via crafted configuration parameters. The script automates the exploitation process by scanning targets, extracting tokens, and sending malicious payloads.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: phpMyAdmin (versions affected by CVE-2009-1151)
No auth needed
Prerequisites: Target running vulnerable phpMyAdmin with accessible setup.php · Network connectivity to the target
devstral-2 · analyzed Feb 18, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Greg Ose, pagvac, egypt · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/phpmyadmin_config.rb

This Metasploit module exploits a vulnerability in phpMyAdmin's setup feature (CVE-2009-1151) to inject arbitrary PHP code into the configuration file. It retrieves a session cookie and CSRF token, crafts a malicious configuration payload, and triggers execution by accessing the compromised file.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: phpMyAdmin versions 2.11.x < 2.11.9.5 and 3.x < 3.1.3.1
No auth needed
Prerequisites: Access to the phpMyAdmin setup script · Network connectivity to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

PhpMyAdmin Scripts - Remote Code Execution
HIGHby princechaddha
Shodan: http.title:"phpmyadmin" || http.component:"phpmyadmin" || cpe:"cpe:2.3:a:phpmyadmin:phpmyadmin"
FOFA: title="phpmyadmin" || body="pma_servername" && body="4.8.4"

References (16)

Core 16
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www.phpmyadmin.net/home_page/security/PMASA-2009-3.php
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200906-03.xml
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34642
Broken Link, Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/504191/100/0/threaded
Mailing List vendor-advisory x_refsource_debian
http://www.debian.org/security/2009/dsa-1824
Broken Link vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2009:115
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34236
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34430
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35635
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8921
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35585

Scores

CVSS v3 9.8
EPSS 0.9327
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2022-03-25
VulnCheck KEV 2011-07-29
InTheWild.io 2022-03-25
ENISA EUVD EUVD-2009-1151
CWE
CWE-94
Status published
Products (3)
debian/debian_linux 4.0
debian/debian_linux 5.0
phpmyadmin/phpmyadmin 2.11.0 - 2.11.9.5
Published Mar 26, 2009
KEV Added Mar 25, 2022
Tracked Since Feb 18, 2026