|
|||
Rule General Information |
---|
Release Date: | 2019-06-27 | |
Rule Name: | phpmyadmin 3.5.2.2 Backdoor Access and Code Execution Vulnerability (CVE-2012-5159) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_sync.php, which allows remote attackers to execute arbitrary PHP code via an eval injection attack. | |
Impact: | An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software. | |
Affected OS: | Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others | |
Reference: | SecurityFocusBID:55672 http://seclists.org/oss-sec/2012/q3/562 http://sourceforge.net/blog/phpmyadmin-back-door/ http://www.phpmyadmin.net/home_page/security/PMASA-2012-5.php |
|
Solutions |
---|
The vendors have released upgrade patches to fix vulnerabilities, please visit: http://www.phpmyadmin.net/home_page/security/PMASA-2012-5.php |