CVE-2009-1285Code Injection in Phpmyadmin

CWE-94Code Injection5 documents5 sources
Severity
7.5HIGHNVD
EPSS
0.4%
top 42.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 16
Latest updateMay 2

Description

Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP code into configuration files.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

debiandebian/phpmyadmin< phpmyadmin 4:3.1.3.2-1 (bookworm)
Debianphpmyadmin/phpmyadmin< 4:3.1.3.2-1+3
NVDphpmyadmin/phpmyadmin8 versions+7

Patches

🔴Vulnerability Details

2
GHSA
GHSA-395f-pvp5-hvp6: Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile2022-05-02
OSV
CVE-2009-1285: Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile2009-04-16

📋Vendor Advisories

2
Debian
CVE-2009-1285: phpmyadmin - Static code injection vulnerability in the getConfigFile function in setup/lib/C...2009
Red Hat
phpMyAdmin: Insufficient output sanitizing when generating configuration file fixed in 3.1.3.2 (PMASA-2009-4)