First published: Tue Sep 25 2012(Updated: )
phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_sync.php, which allows remote attackers to execute arbitrary PHP code via an eval injection attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PhpMyAdmin | =3.5.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5159 is considered a critical vulnerability due to its ability to allow remote code execution.
To fix CVE-2012-5159, upgrade to a secure version of phpMyAdmin that is not affected by this vulnerability.
Exploitation of CVE-2012-5159 allows attackers to execute arbitrary PHP code, leading to complete server compromise.
CVE-2012-5159 specifically affects phpMyAdmin version 3.5.2.2 as distributed from the cdnetworks-kr-1 mirror.
You can check the version of phpMyAdmin you are using and look for signs of tampering or unexpected files, particularly in server_sync.php.