← Vulnerability feed

Vulnerability record · CVE-2012-5159 · published 25 September 2012

CVE-2012-5159: phpMyAdmin mirror-distributed backdoor enables PHP code execution

Phpmyadmin · Phpmyadmin

phpMyAdmin 3.5.2.2 distributed by the cdnetworks-kr-1 mirror during an unspecified period in 2012 contained an externally introduced modification (Trojan Horse) in server_sync.php. That injected code allows remote attackers to execute arbitrary PHP code through an eval injection attack. The flaw matters because it is a supply-chain compromise of a widely deployed database administration tool, not a coding bug in the upstream release.

7.5 CVSS 2.0 High EPSS 75% · top 0.5% CWE-94 · Code injection
7.5CVSS 2.0 base score
75%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_sync.php, which allows remote attackers to execute arbitrary PHP code via an eval injection attack.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityA network-reachable, unauthenticated code execution backdoor in a widely used admin tool with very high EPSS, though it is an old, mirror-specific supply-chain incident rather than a current upstream vulnerability.

What it is

phpMyAdmin 3.5.2.2 distributed by the cdnetworks-kr-1 mirror during an unspecified period in 2012 contained an externally introduced modification (Trojan Horse) in server_sync.php. That injected code allows remote attackers to execute arbitrary PHP code through an eval injection attack. The flaw matters because it is a supply-chain compromise of a widely deployed database administration tool, not a coding bug in the upstream release.

Impact

An attacker can execute arbitrary PHP code on the server running the affected phpMyAdmin copy, which typically yields access to database credentials and the underlying host. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.

Attack surface

Reachable over the network with no authentication required per the AV:N/AC:L/Au:N vector, via requests that reach the trojanized server_sync.php. No user interaction is indicated in the record.

Exploitation

Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is very high at 0.745 probability (99.47th percentile), indicating strong predicted exploitation activity. The record does not state whether public exploit code exists.

What to do

  • Replace any phpMyAdmin 3.5.2.2 obtained from the cdnetworks-kr-1 mirror with a clean copy from the official phpMyAdmin distribution and verify integrity.
  • If the mirror copy was ever deployed, treat the host as compromised: rotate database credentials, application secrets and any keys reachable from that server.
  • Restrict network access to phpMyAdmin interfaces to trusted management networks rather than exposing them broadly.
  • Review server_sync.php and other files for unexpected eval or obfuscated code before restoring service.
  • Track the vendor advisory PMASA-2012-5 for the official remediation guidance.

Detection

  • Search web server and application logs for requests to server_sync.php, especially from unexpected source addresses.
  • Scan deployed phpMyAdmin files for eval usage or content that differs from the official release checksums.
  • Monitor for outbound connections or process execution spawned by the web server user that are inconsistent with normal phpMyAdmin behavior.
  • Hunt for unexpected file modifications in the phpMyAdmin directory tree around the 2012 distribution window.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-5159 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2009-1151phpMyAdmin setup.php code injection enables remote PHP executionphpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 contains a static code injection flaw in setup.php. The save action lets a remote attacker w…KEVEPSS 97%analysed10.0CVE-2008-7251Phpmyadmin permissions and access controls vulnerabilitylibraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 creates a temporary directory with 0777 permissions, which has unknown impact and attack…EPSS 2.7%10.0CVE-2008-7252Phpmyadmin vulnerabilitylibraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and attack vect…EPSS 2.7%10.0CVE-2007-0203Phpmyadmin vulnerabilityMultiple unspecified vulnerabilities in phpMyAdmin before 2.9.2-rc1 have unknown impact and attack vectors.EPSS 1.9%10.0CVE-2004-1147Phpmyadmin vulnerabilityphpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands v…EPSS 12%9.8CVE-2020-22452Phpmyadmin sql injection vulnerabilitySQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_…EPSS 1.7%9.8CVE-2020-26935phpMyAdmin SearchController SQL injection via search featurephpMyAdmin before 4.9.6 and 5.x before 5.0.3 contains a SQL injection flaw in SearchController's handling of SQL statements in the search feature. An…EPSS 67%analysed9.8CVE-2019-19617Phpmyadmin vulnerabilityphpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.ph…EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2012-5159), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.