Vulnerability record · CVE-2012-5159 · published 25 September 2012
CVE-2012-5159: phpMyAdmin mirror-distributed backdoor enables PHP code execution
Phpmyadmin · Phpmyadmin
phpMyAdmin 3.5.2.2 distributed by the cdnetworks-kr-1 mirror during an unspecified period in 2012 contained an externally introduced modification (Trojan Horse) in server_sync.php. That injected code allows remote attackers to execute arbitrary PHP code through an eval injection attack. The flaw matters because it is a supply-chain compromise of a widely deployed database administration tool, not a coding bug in the upstream release.
Description
phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_sync.php, which allows remote attackers to execute arbitrary PHP code via an eval injection attack.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityA network-reachable, unauthenticated code execution backdoor in a widely used admin tool with very high EPSS, though it is an old, mirror-specific supply-chain incident rather than a current upstream vulnerability.
What it is
phpMyAdmin 3.5.2.2 distributed by the cdnetworks-kr-1 mirror during an unspecified period in 2012 contained an externally introduced modification (Trojan Horse) in server_sync.php. That injected code allows remote attackers to execute arbitrary PHP code through an eval injection attack. The flaw matters because it is a supply-chain compromise of a widely deployed database administration tool, not a coding bug in the upstream release.
Impact
An attacker can execute arbitrary PHP code on the server running the affected phpMyAdmin copy, which typically yields access to database credentials and the underlying host. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.
Attack surface
Reachable over the network with no authentication required per the AV:N/AC:L/Au:N vector, via requests that reach the trojanized server_sync.php. No user interaction is indicated in the record.
Exploitation
Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is very high at 0.745 probability (99.47th percentile), indicating strong predicted exploitation activity. The record does not state whether public exploit code exists.
What to do
- Replace any phpMyAdmin 3.5.2.2 obtained from the cdnetworks-kr-1 mirror with a clean copy from the official phpMyAdmin distribution and verify integrity.
- If the mirror copy was ever deployed, treat the host as compromised: rotate database credentials, application secrets and any keys reachable from that server.
- Restrict network access to phpMyAdmin interfaces to trusted management networks rather than exposing them broadly.
- Review server_sync.php and other files for unexpected eval or obfuscated code before restoring service.
- Track the vendor advisory PMASA-2012-5 for the official remediation guidance.
Detection
- Search web server and application logs for requests to server_sync.php, especially from unexpected source addresses.
- Scan deployed phpMyAdmin files for eval usage or content that differs from the official release checksums.
- Monitor for outbound connections or process execution spawned by the web server user that are inconsistent with normal phpMyAdmin behavior.
- Hunt for unexpected file modifications in the phpMyAdmin directory tree around the 2012 distribution window.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-5159 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-5159), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.