S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2009-1151 Scanner

CVE-2009-1151 scanner - Code Injection vulnerability in phpMyAdmin

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2009-1151
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

PhpMyAdmin is a popular software tool used for managing MySQL databases through a web interface. It provides users with a wide range of functionalities, including the creation and management of databases, tables, and queries. PhpMyAdmin is widely used by website owners and developers around the world for its user-friendly interface, versatility and ease of use.

CVE-2009-1151 is a static code injection vulnerability that was found in phpMyAdmin. It affects versions 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1. This vulnerability allows remote attackers to inject arbitrary PHP code into configuration files through the save action function. This means that an attacker can execute malicious code and take control of the entire system, giving them free reign over sensitive information.

When exploited, the CVE-2009-1151 vulnerability can lead to disastrous consequences. Attackers can inject malicious code and execute it, which could lead to data theft, data modification, and even system crashes or damage. Furthermore, the attacker may gain unauthorized access to sensitive information such as passwords, usernames, and other confidential data stored in the database.

Thanks to the professional features of the s4e.io platform, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. The platform offers real-time scanning, advanced security features, and detailed reports on any potential threats and vulnerabilities. By following their suggestions and applying their recommendations, users can ensure that their systems are protected and secured from attacks.

 

REFERENCES

Solution Advice

To protect themselves against the CVE-2009-1151 vulnerability and other similar attacks, users and developers must implement the following precautions:

  • Keep all software up-to-date, including phpMyAdmin and other associated libraries.
  • Implement a Web Application Firewall (WAF) to help detect and prevent attacks.
  • Only use trusted and secure plugins and themes for phpMyAdmin.
  • Limit the number of users who have access to configuration files and restrict the use of phpMyAdmin to authorized users only.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2009-1151 scanner - Code Injection vulnerability in phpMyAdmin S4E