EXPOSURES › CVE-2009-1151
CVE-2009-1151
HIGH ⌖ ON CISA KEV · EXPLOITEDA crafted POST request to phpMyAdmin's setup script can inject arbitrary PHP code into the generated configuration file, enabling remote code execution.
An attacker can trick the setup script into including malicious PHP code in the configuration file, granting remote code execution. DIB organizations must ensure setup scripts are never executed in production and that phpMyAdmin is patched to prevent exploitation of this actively exploited vulnerability.
Shame score — This vulnerability is actively exploited in the wild and allows remote code execution, representing a severe, avoidable security failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file.