ID:4242 - Exploit for Code Injection in phpMyAdmin - CVE-2012-5159

 
Main Vulnerability Database Exploits ID:4242 - Exploit for Code Injection in phpMyAdmin - CVE-2012-5159

ID:4242 - Exploit for Code Injection in phpMyAdmin - CVE-2012-5159

Published: August 11, 2020


Vulnerability identifier: #VU43479
Vulnerability risk: Medium
CVE-ID: CVE-2012-5159
CWE-ID: CWE-94
Exploitation vector: Remote access
Vulnerable software:
phpMyAdmin

Link to public exploit:


Vulnerability description

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_sync.php, which allows remote attackers to execute arbitrary PHP code via an eval injection attack. Although not found in all distributions of this software, the vulnerability was scored assuming that it was. End-users will need to identify whether their distribution does in fact contain the vulnerability.


Remediation

Install update from vendor's website.