Release date:
Updated on:
Affected Systems:
PhpMyAdmin 3.5.2.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 55672
Cve id: CVE-2012-5159
PhpMyAdmin is written in PHP and can be used to control and operate MySQL databases on the web.
PhpMyAdmin distribution through the "cdnetworks-kr-1" SourceForge mirror system phpMyAdmin contains a trojan named server_sync.php that allows remote attackers to execute arbitrary commands by calling eval () attacks.
<* Source: Tencent Security Response Center
Link: http://web.nvd.nist.gov/view/vuln/detail? VulnId = CVE-2012-5159
Http://secunia.com/advisories/50703/
Http://www.phpmyadmin.net/home_page/security/PMASA-2012-5.php
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PhpMyAdmin
----------
PhpMyAdmin has released a Security Bulletin (PMASA-2012-5) and corresponding patches for this:
PMASA-2012-5: PMASA-2012-5
Link: http://www.phpmyadmin.net/home_page/security/PMASA-2012-5.php