目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2009-1151 PoC — phpMyAdmin setup.php脚本PHP代码注入漏洞

来源
关联漏洞
标题: phpMyAdmin setup.php脚本PHP代码注入漏洞 (CVE-2009-1151)
Description:phpMyAdmin是用PHP编写的工具,用于通过WEB管理MySQL。 phpMyAdmin的Setup脚本用于生成配置。如果远程攻击者向该脚本提交了特制的POST请求的话,就可能在生成的config.inc.php配置文件中包含任意PHP代码。由于配置文件被保存到了服务器上,未经认证的远程攻击者可以利用这个漏洞执行任意PHP代码。
Description
Based on the x.pl exploit/loader script for CVE-2009-1151
介绍
This is an old perl scanner I found for the php my admin exploit that's from 2009. 
I got bored and figured I would practice perl and learn a bit about an older language and convert it to python. 
This is for educational purposes mostly because this exploit being well over a decade old I wouldn't suspect a large impact by any means from publishing. 
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →