Description
phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_sync.php, which allows remote attackers to execute arbitrary PHP code via an eval injection attack.
Remediation
References
Related Vulnerabilities
Caddy Web Server Improper Authentication Vulnerability (CVE-2026-30851)
Apache HTTP Server Other Vulnerability (CVE-2003-0192)
PHP Out-of-bounds Read Vulnerability (CVE-2020-7059)
WordPress Plugin ReFlex Gallery Cross-Site Scripting (3.1.4)
WordPress Plugin Contact Form 7 Database Addon-CFDB7 CSV Injection (1.2.5.5)