CVE-2009-1151
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- phpMyAdmin Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 95% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-94
מוצרים מושפעים
phpmyadmin: phpmyadmin; debian: debian linux
קישורים
- http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/branches/MAINT_2_11_9/… Vendor Advisory
- http://secunia.com/advisories/34430 Broken LinkVendor Advisory
- http://secunia.com/advisories/34642 Broken LinkVendor Advisory
- http://secunia.com/advisories/35585 Broken LinkVendor Advisory
- http://secunia.com/advisories/35635 Broken LinkVendor Advisory
- http://www.phpmyadmin.net/home_page/security/PMASA-2009-3.php PatchVendor Advisory
- http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/branches/MAINT_2_11_9/… Vendor Advisory
- http://secunia.com/advisories/34430 Broken LinkVendor Advisory
- http://secunia.com/advisories/34642 Broken LinkVendor Advisory
- http://secunia.com/advisories/35585 Broken LinkVendor Advisory