Loading
Generated remediation guidance and an executive summary. No account required.
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.
Use CWE-94, Phpmyadmin vendor hub and Phpmyadmin product page to widen CVE-2009-1151 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-22452, CVE-2020-26935 and CVE-2020-22278 for nearby disclosures in the same product family.