CVE-2009-1151
CRITICAL KEV NUCLEIphpMyAdmin 2.11.0-2.11.9.4 and 3.x < 3.1.3.1 - Remote Code Injection via Setup Configuration Save
Title source: llmExploitation Summary
CVE-2009-1151 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 25, 2022.
EIP tracks 7 public exploits from researchers including Metasploit, Hacking Expose!, Adrian _pagvac_ Pastor, including a Metasploit module exploits/unix/webapp/phpmyadmin_config.
A Nuclei detection template is also available.
AI-analyzed exploit summary This Metasploit module exploits a code injection vulnerability in phpMyAdmin's setup feature, allowing arbitrary PHP code execution by injecting payloads into the configuration file. It targets versions 2.11.x < 2.11.9.5 and 3.x < 3.1.3.1.
Description
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.
Exploits (7)
This Metasploit module exploits a code injection vulnerability in phpMyAdmin's setup feature, allowing arbitrary PHP code execution by injecting payloads into the configuration file. It targets versions 2.11.x < 2.11.9.5 and 3.x < 3.1.3.1.
This script scans for phpMyAdmin installations using Google dorks and checks for potential vulnerabilities, including CVE-2009-1151. It does not contain a full exploit but identifies targets for further exploitation.
This exploit leverages a PHP code injection vulnerability in phpMyAdmin's setup.php script to achieve remote code execution (RCE). It injects malicious PHP code into the configuration file, allowing arbitrary command execution via HTTP GET parameters.
This repository contains a functional exploit for CVE-2009-1151, a PHP code injection vulnerability in phpMyAdmin's setup script. The exploit injects malicious PHP code into the configuration file, enabling remote command execution.
The repository contains only a minimal README with a CVE reference and no functional exploit code or technical details. It appears to be a placeholder or stub.
This repository contains a Python script that exploits CVE-2009-1151, a vulnerability in phpMyAdmin's setup script allowing remote code execution via crafted configuration parameters. The script automates the exploitation process by scanning targets, extracting tokens, and sending malicious payloads.
This Metasploit module exploits a vulnerability in phpMyAdmin's setup feature (CVE-2009-1151) to inject arbitrary PHP code into the configuration file. It retrieves a session cookie and CSRF token, crafts a malicious configuration payload, and triggers execution by accessing the compromised file.
Nuclei Templates (1)
http.title:"phpmyadmin" || http.component:"phpmyadmin" || cpe:"cpe:2.3:a:phpmyadmin:phpmyadmin"
title="phpmyadmin" || body="pma_servername" && body="4.8.4"
References (16)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H