phpMyAdmin 'server_sync.php' Backdoor Vulnerability
BID:55672
Info
phpMyAdmin 'server_sync.php' Backdoor Vulnerability
| Bugtraq ID: | 55672 |
| Class: | Unknown |
| CVE: |
CVE-2012-5159 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 25 2012 12:00AM |
| Updated: | Sep 26 2012 06:30AM |
| Credit: | Tencent Security Response Center |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
phpMyAdmin 'server_sync.php' Backdoor Vulnerability
phpMyAdmin is prone to a backdoor vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the application. Successful attacks will compromise the affected application.
phpMyAdmin 3.5.2.2 is vulnerable; other versions may also be affected.
phpMyAdmin is prone to a backdoor vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the application. Successful attacks will compromise the affected application.
phpMyAdmin 3.5.2.2 is vulnerable; other versions may also be affected.
Exploit / POC
phpMyAdmin 'server_sync.php' Backdoor Vulnerability
An attacker can use readily available tools to exploit this issue.
The following exploit is available:
An attacker can use readily available tools to exploit this issue.
The following exploit is available:
Solution / Fix
phpMyAdmin 'server_sync.php' Backdoor Vulnerability
Solution:
The vendor released an update. Please see the references for details.
Solution:
The vendor released an update. Please see the references for details.