CVE-2012-5159
phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_sync.php, which allows remote attackers to execute arbitrary PHP code via an eval injection attack.
- Affected products
- Phpmyadmin
- Phpmyadmin
- = 3.5.2.2
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 74.5% (99th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2012-09-25
CVE-2012-5159 at NVD
4 known exploits for CVE-2012-5159
Proof-of-concept code and exploit modules indexed by Sploitus