phpMyAdmin是用PHP编写的工具,用于通过WEB管理MySQL。 phpMyAdmin的Setup脚本用于生成配置。如果远程攻击者向该脚本提交了特制的POST请求的话,就可能在生成的config.inc.php配置文件中包含任意PHP代码。由于配置文件被保存到了服务器上,未经认证的远程攻击者可以利用这个漏洞执行任意PHP代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | phpMyAdmin '/scripts/setup.php' PHP Code Injection RCE PoC (CVE-2009-1151) | https://github.com/adpast/pocs | POC Details |
| 2 | phpMyAdmin '/scripts/setup.php' PHP Code Injection RCE PoC (CVE-2009-1151) | https://github.com/pagvac/pocs | POC Details |
| 3 | Based on the x.pl exploit/loader script for CVE-2009-1151 | https://github.com/ItaIia/PhpMyAdmin | POC Details |
| 4 | Based on the x.pl exploit/loader script for CVE-2009-1151 | https://github.com/e-Thug/PhpMyAdmin | POC Details |
| 5 | CVE-2009-1151, phpMyAdmin의 set.up | https://github.com/mr-won/ZmEu | POC Details |
| 6 | PhpMyAdmin Scripts 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 are susceptible to a remote code execution in setup.php that allows remote attackers to inject arbitrary PHP code into a configuration file via the save action. Combined with the ability to save files on server, this can allow unauthenticated users to execute arbitrary PHP code. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2009/CVE-2009-1151.yaml | POC Details |
| 7 | CVE-2009-1151, phpMyAdmin의 set.up | https://github.com/user20252228/ZmEu | POC Details |
| 8 | CVE-2009-1151, phpMyAdmin의 set.up | https://github.com/tpdlshdmlrkfmcla/ZmEu | POC Details |
No public POC found.
Login to generate AI POC| CVE-2008-6528 | Tmax Soft JEUS Alternate Data Stream 源代码信息泄露漏洞 | |
| CVE-2009-1148 | phpMyAdmin BLOB Streaming 多个输入验证漏洞 | |
| CVE-2009-1149 | phpMyAdmin BLOB Streaming 多个输入验证漏洞 | |
| CVE-2009-1150 | phpMyAdmin 'export page' 跨站脚本攻击漏洞 | |
| CVE-2009-1152 | Siemens Gigaset SE461 WiMAX路由器远程拒绝服务漏洞 | |
| CVE-2008-6529 | eZoneScripts Living Local 'listtest.php' 跨站脚本攻击漏洞 | |
| CVE-2008-6530 | eZoneScripts Living Local php script 'editimage.php'远程任意文件上传漏洞 | |
| CVE-2008-6531 | Atlassian JIRA 远程安全绕过漏洞 | |
| CVE-2008-6532 | Drupal跨站请求伪造漏洞 | |
| CVE-2008-6533 | Drupal Deleted Input Format 跨站脚本攻击漏洞 | |
| CVE-2008-6534 | Vwsolutions Null FTP Server 'SITE'命令任意指令注入漏洞 | |
| CVE-2008-6535 | PayPal eStores 'admin/settings.php'权限许可和访问控制漏洞 |
No comments yet