<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: CVE-2009-1151: phpMyAdmin Remote Code Execution Proof of Concept</title>
	<atom:link href="http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Sat, 02 Feb 2013 17:50:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: DenisFrati.it &#187; Archive &#187; A phishing case &#8211; 1</title>
		<link>http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/comment-page-1/#comment-130345</link>
		<dc:creator>DenisFrati.it &#187; Archive &#187; A phishing case &#8211; 1</dc:creator>
		<pubDate>Wed, 04 May 2011 12:42:45 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3254#comment-130345</guid>
		<description>[...] versione di PhpMyAdmin Ã¨ vulnerabile ad un exploit che causa l&#8217;inclusione di un file di configurazione config.inc.php modificato in Â modo tale [...]</description>
		<content:encoded><![CDATA[<p>[...] versione di PhpMyAdmin Ã¨ vulnerabile ad un exploit che causa l&#8217;inclusione di un file di configurazione config.inc.php modificato in Â modo tale [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Golf</title>
		<link>http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/comment-page-1/#comment-129010</link>
		<dc:creator>Golf</dc:creator>
		<pubDate>Tue, 14 Sep 2010 07:30:06 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3254#comment-129010</guid>
		<description>Ran the script. Love it!</description>
		<content:encoded><![CDATA[<p>Ran the script. Love it!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: unda</title>
		<link>http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/comment-page-1/#comment-128729</link>
		<dc:creator>unda</dc:creator>
		<pubDate>Sun, 22 Aug 2010 09:48:50 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3254#comment-128729</guid>
		<description>Well very cool to share this ... Thx</description>
		<content:encoded><![CDATA[<p>Well very cool to share this &#8230; Thx</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: droope</title>
		<link>http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/comment-page-1/#comment-128536</link>
		<dc:creator>droope</dc:creator>
		<pubDate>Thu, 03 Jun 2010 21:06:22 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3254#comment-128536</guid>
		<description>Woah man.... so many websites running this version of php my admin! 

Awesome find. Thanks for sharing.</description>
		<content:encoded><![CDATA[<p>Woah man&#8230;. so many websites running this version of php my admin! </p>
<p>Awesome find. Thanks for sharing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: yadianna</title>
		<link>http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/comment-page-1/#comment-128382</link>
		<dc:creator>yadianna</dc:creator>
		<pubDate>Mon, 22 Mar 2010 01:57:05 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3254#comment-128382</guid>
		<description>I saw the security issue on ISPConfig â€“ Community. Is it a problem with every phpMyAdmin-Version?</description>
		<content:encoded><![CDATA[<p>I saw the security issue on ISPConfig â€“ Community. Is it a problem with every phpMyAdmin-Version?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Backup de tus bases de datos con phpMyAdmin</title>
		<link>http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/comment-page-1/#comment-127877</link>
		<dc:creator>Backup de tus bases de datos con phpMyAdmin</dc:creator>
		<pubDate>Wed, 30 Sep 2009 14:34:07 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3254#comment-127877</guid>
		<description>[...] enormemente si tienes instalado phpMyAdmin. Ten cuidado con la versiÃ³n que tienes porque hay varios exploits que afectan a la misma, y si no tienes la Ãºltima versiÃ³n puede haber [...]</description>
		<content:encoded><![CDATA[<p>[...] enormemente si tienes instalado phpMyAdmin. Ten cuidado con la versiÃ³n que tienes porque hay varios exploits que afectan a la misma, y si no tienes la Ãºltima versiÃ³n puede haber [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: phpMyAdmin Remote Code Execution: how to mess with disaster</title>
		<link>http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/comment-page-1/#comment-127848</link>
		<dc:creator>phpMyAdmin Remote Code Execution: how to mess with disaster</dc:creator>
		<pubDate>Wed, 16 Sep 2009 07:57:47 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3254#comment-127848</guid>
		<description>[...] For a full documentation about the exploit, please read this article. [...]</description>
		<content:encoded><![CDATA[<p>[...] For a full documentation about the exploit, please read this article. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Corina Mandel</title>
		<link>http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/comment-page-1/#comment-127847</link>
		<dc:creator>Corina Mandel</dc:creator>
		<pubDate>Wed, 16 Sep 2009 07:45:28 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3254#comment-127847</guid>
		<description>We got this tip (the link) from a another programmer. And in fact: our phpMyAdmin-version was outdated and vulnerable :(</description>
		<content:encoded><![CDATA[<p>We got this tip (the link) from a another programmer. And in fact: our phpMyAdmin-version was outdated and vulnerable :(</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: [RESOLVED] [error] an unknown filter was not added: PHP</title>
		<link>http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/comment-page-1/#comment-127844</link>
		<dc:creator>[RESOLVED] [error] an unknown filter was not added: PHP</dc:creator>
		<pubDate>Tue, 15 Sep 2009 12:30:12 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3254#comment-127844</guid>
		<description>[...] Last week one of our servers was deeply atacked by a hacker using a phpMyAdmin&#8217;s security bug (I&#8217;ll tell you more about it in a subsequent post, but you can read more HERE). [...]</description>
		<content:encoded><![CDATA[<p>[...] Last week one of our servers was deeply atacked by a hacker using a phpMyAdmin&#8217;s security bug (I&#8217;ll tell you more about it in a subsequent post, but you can read more HERE). [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hahnefeld</title>
		<link>http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/comment-page-1/#comment-127819</link>
		<dc:creator>Hahnefeld</dc:creator>
		<pubDate>Thu, 03 Sep 2009 17:56:42 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3254#comment-127819</guid>
		<description>I saw the security issue on ISPConfig - Community. Is it a problem with every phpMyAdmin-Version?</description>
		<content:encoded><![CDATA[<p>I saw the security issue on ISPConfig &#8211; Community. Is it a problem with every phpMyAdmin-Version?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kecemplungkalen</title>
		<link>http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/comment-page-1/#comment-127478</link>
		<dc:creator>kecemplungkalen</dc:creator>
		<pubDate>Fri, 12 Jun 2009 21:24:23 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3254#comment-127478</guid>
		<description>but nice pagvac :)</description>
		<content:encoded><![CDATA[<p>but nice pagvac :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kecemplungkalen</title>
		<link>http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/comment-page-1/#comment-127476</link>
		<dc:creator>kecemplungkalen</dc:creator>
		<pubDate>Fri, 12 Jun 2009 20:53:21 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3254#comment-127476</guid>
		<description>old bug but new tread :) good job PDP i was testing for all indonesian phpmyadmin work fine :)</description>
		<content:encoded><![CDATA[<p>old bug but new tread :) good job PDP i was testing for all indonesian phpmyadmin work fine :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: adriensk8</title>
		<link>http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/comment-page-1/#comment-127474</link>
		<dc:creator>adriensk8</dc:creator>
		<pubDate>Fri, 12 Jun 2009 16:04:12 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3254#comment-127474</guid>
		<description>Excellent....!!</description>
		<content:encoded><![CDATA[<p>Excellent&#8230;.!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pagvac</title>
		<link>http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/comment-page-1/#comment-127462</link>
		<dc:creator>pagvac</dc:creator>
		<pubDate>Thu, 11 Jun 2009 11:25:35 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3254#comment-127462</guid>
		<description>@ToR: thanks for testing the script on other versions bro 8-)</description>
		<content:encoded><![CDATA[<p>@ToR: thanks for testing the script on other versions bro 8-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rosko</title>
		<link>http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/comment-page-1/#comment-127461</link>
		<dc:creator>rosko</dc:creator>
		<pubDate>Thu, 11 Jun 2009 07:51:11 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3254#comment-127461</guid>
		<description>as u said &quot;nice reminder&quot;</description>
		<content:encoded><![CDATA[<p>as u said &#8220;nice reminder&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ToR</title>
		<link>http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/comment-page-1/#comment-127458</link>
		<dc:creator>ToR</dc:creator>
		<pubDate>Wed, 10 Jun 2009 18:36:04 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3254#comment-127458</guid>
		<description>Nice work, works well also on v. 2.11.7.1 and 2.11.7 ;)

ToR</description>
		<content:encoded><![CDATA[<p>Nice work, works well also on v. 2.11.7.1 and 2.11.7 ;)</p>
<p>ToR</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pagvac</title>
		<link>http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/comment-page-1/#comment-127448</link>
		<dc:creator>pagvac</dc:creator>
		<pubDate>Wed, 10 Jun 2009 08:45:49 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3254#comment-127448</guid>
		<description>@Jose: thanks a lot for that. it should be quite simple to modify the PoC to exploit CVE-2009-1285. sweet!

will give it a try if i have some free time and/or feel inspired :)</description>
		<content:encoded><![CDATA[<p>@Jose: thanks a lot for that. it should be quite simple to modify the PoC to exploit CVE-2009-1285. sweet!</p>
<p>will give it a try if i have some free time and/or feel inspired :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jose Miguel Esparza</title>
		<link>http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/comment-page-1/#comment-127447</link>
		<dc:creator>Jose Miguel Esparza</dc:creator>
		<pubDate>Wed, 10 Jun 2009 08:42:00 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3254#comment-127447</guid>
		<description>Hi there! Good PoC! I played with this vuln some weeks ago and I had had no time to write anything. It could be a good idea to add the vuln affecting the 3.1.3.1 version: http://www.phpmyadmin.net/home_page/security/PMASA-2009-4.php

It&#039;s the same concept but change some files and functions (the setup page is /setup/config.php now, for example). The vulnerable package to play with: http://sourceforge.net/project/downloading.php?group_id=23067&amp;filename=phpMyAdmin-3.1.3.1-all-languages.tar.gz

Cheers!</description>
		<content:encoded><![CDATA[<p>Hi there! Good PoC! I played with this vuln some weeks ago and I had had no time to write anything. It could be a good idea to add the vuln affecting the 3.1.3.1 version: <a href="http://www.phpmyadmin.net/home_page/security/PMASA-2009-4.php" rel="nofollow">http://www.phpmyadmin.net/home.....2009-4.php</a></p>
<p>It&#8217;s the same concept but change some files and functions (the setup page is /setup/config.php now, for example). The vulnerable package to play with: <a href="http://sourceforge.net/project/downloading.php?group_id=23067&#038;filename=phpMyAdmin-3.1.3.1-all-languages.tar.gz" rel="nofollow">http://sourceforge.net/project.....ges.tar.gz</a></p>
<p>Cheers!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pagvac</title>
		<link>http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/comment-page-1/#comment-127446</link>
		<dc:creator>pagvac</dc:creator>
		<pubDate>Wed, 10 Jun 2009 06:41:54 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3254#comment-127446</guid>
		<description>thanks for the feedback guys. btw, here are some vulnerable versions in case anyone wants to experiment with the script:

http://sourceforge.net/project/downloading.php?group_id=23067&amp;filename=phpMyAdmin-3.0.0-english.tar.gz&amp;a=95960040
http://sourceforge.net/project/downloading.php?group_id=23067&amp;filename=phpMyAdmin-3.0.1.1-english.tar.gz&amp;a=95960040
http://sourceforge.net/project/downloading.php?group_id=23067&amp;filename=phpMyAdmin-2.11.4-english.tar.gz&amp;a=95960040
http://sourceforge.net/project/downloading.php?group_id=23067&amp;filename=phpMyAdmin-2.11.9.3-english.tar.gz&amp;a=95960040
http://sourceforge.net/project/downloading.php?group_id=23067&amp;filename=phpMyAdmin-2.11.9.4-english.tar.gz&amp;a=95960040</description>
		<content:encoded><![CDATA[<p>thanks for the feedback guys. btw, here are some vulnerable versions in case anyone wants to experiment with the script:</p>
<p><a href="http://sourceforge.net/project/downloading.php?group_id=23067&#038;filename=phpMyAdmin-3.0.0-english.tar.gz&#038;a=95960040" rel="nofollow">http://sourceforge.net/project.....a=95960040</a><br />
<a href="http://sourceforge.net/project/downloading.php?group_id=23067&#038;filename=phpMyAdmin-3.0.1.1-english.tar.gz&#038;a=95960040" rel="nofollow">http://sourceforge.net/project.....a=95960040</a><br />
<a href="http://sourceforge.net/project/downloading.php?group_id=23067&#038;filename=phpMyAdmin-2.11.4-english.tar.gz&#038;a=95960040" rel="nofollow">http://sourceforge.net/project.....a=95960040</a><br />
<a href="http://sourceforge.net/project/downloading.php?group_id=23067&#038;filename=phpMyAdmin-2.11.9.3-english.tar.gz&#038;a=95960040" rel="nofollow">http://sourceforge.net/project.....a=95960040</a><br />
<a href="http://sourceforge.net/project/downloading.php?group_id=23067&#038;filename=phpMyAdmin-2.11.9.4-english.tar.gz&#038;a=95960040" rel="nofollow">http://sourceforge.net/project.....a=95960040</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: å¢¨å°”æœ¬</title>
		<link>http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/comment-page-1/#comment-127445</link>
		<dc:creator>å¢¨å°”æœ¬</dc:creator>
		<pubDate>Wed, 10 Jun 2009 06:32:54 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3254#comment-127445</guid>
		<description>This is some great script to deal with phpMyAdmin. Thanks for sharing.</description>
		<content:encoded><![CDATA[<p>This is some great script to deal with phpMyAdmin. Thanks for sharing.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
