The phpMyAdmin Supply Chain Attack
Updated 5 Oct 2026 · Incident date 22 Sept 2012 · source tarball
phpMyAdmin 3.5.2.2 (official zip) -> phpMyAdmin-3.5.2.2-all-languages.zip from the cdnetworks-kr-1 SourceForge mirrorserver_sync.phpphpMyAdmin 3.5.2.2 was the version with a backdoor when it came from the SourceForge mirror cdnetworks-kr-1 in September 2012. The bad zip was phpMyAdmin-3.5.2.2-all-languages.zip.
The zip held a new file named server_sync.php. The file lets a remote attacker run PHP code on the server. The flaw has the id CVE-2012-5159.
What happened
A copy of phpMyAdmin 3.5.2.2 on one SourceForge mirror held a backdoor that the official release did not have. The phpMyAdmin team published advisory PMASA-2012-5 on 25 September 2012 and rated it critical.
The advisory names the mirror cdnetworks-kr-1. The advisory says two files differ. The new file server_sync.php contains a backdoor for remote PHP code execution. The file js/cross_framing_protection.js was also modified. The advisory credits the Tencent Security Response Center for the report.
The GitHub advisory describes the new file as an eval injection. A remote attacker can run any PHP code. Exploit-DB explains the trigger. An attacker sends an HTTP POST request to server_sync.php with a parameter named c that holds the payload as hex. No login is needed. Exploit-DB lists a public exploit that appeared on 10 October 2012.
Affected versions
- phpMyAdmin 3.5.2.2, only the file
phpMyAdmin-3.5.2.2-all-languages.zipfrom thecdnetworks-kr-1SourceForge mirror. - The GitHub advisory lists the affected and patched version ranges as unknown. Use the presence of the file
server_sync.phpas the test.
Indicators of compromise
- A file named
server_sync.phpin the phpMyAdmin folder. The genuine release does not have it. - A modified
js/cross_framing_protection.js. - HTTP POST requests to
/server_sync.phpwith a parameterc=in your web server logs (Exploit-DB).
How to check
You can search the web root for the backdoor file. Run this command and change the path to your own web root. It only reads files.
find /var/www -name server_sync.php
You can also search the web server logs for requests to the file.
grep "server_sync.php" /var/log/apache2/access.log*
Any result for the file means the install came from the bad zip. A log entry with a POST request means that someone used it. The log path is an example. Use the path of your server.
What to do now
- Search for
server_sync.phpin every phpMyAdmin install. - If the file exists, download phpMyAdmin again from a trusted mirror. This is the fix that the advisory gives.
- Delete the old install folder. Do not delete only the one file, because
js/cross_framing_protection.jswas also changed. - Check the web server logs for POST requests to the file. If you find any, treat the server as compromised. Run a full review of the server and rotate database and server credentials.
- Check the downloaded checksum or signature against the official release before you install.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 81 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED server_sync.php It now downloads from the internet and runs other programs. It did not before.
Frequently asked questions
Which phpMyAdmin version had the backdoor?
phpMyAdmin 3.5.2.2, only the file phpMyAdmin-3.5.2.2-all-languages.zip from the cdnetworks-kr-1 SourceForge mirror. The flaw is CVE-2012-5159.
How do I know if my phpMyAdmin install has the backdoor?
Look for a file named server_sync.php in the phpMyAdmin folder. The genuine release does not have it. If the file exists, download phpMyAdmin again from a trusted mirror.
What does the server_sync.php backdoor do?
It runs PHP code that a remote attacker sends in an HTTP POST request. The request carries a parameter named c with the payload as hex. No login is needed.
Sources
More supply chain attacks
- XZ Utils backdoor 24 Feb 2024
- Webmin SourceForge build backdoor 1 Apr 2018
- vsftpd 2.3.4 backdoor 30 Jun 2011
- ProFTPD 1.3.3c source tarball backdoor 28 Nov 2010
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.