The phpMyAdmin Supply Chain Attack

Updated 5 Oct 2026 · Incident date 22 Sept 2012 · source tarball

PackagephpMyAdmin 3.5.2.2 (official zip) -> phpMyAdmin-3.5.2.2-all-languages.zip from the cdnetworks-kr-1 SourceForge mirror
Fileserver_sync.php

phpMyAdmin 3.5.2.2 was the version with a backdoor when it came from the SourceForge mirror cdnetworks-kr-1 in September 2012. The bad zip was phpMyAdmin-3.5.2.2-all-languages.zip.

The zip held a new file named server_sync.php. The file lets a remote attacker run PHP code on the server. The flaw has the id CVE-2012-5159.

What happened

A copy of phpMyAdmin 3.5.2.2 on one SourceForge mirror held a backdoor that the official release did not have. The phpMyAdmin team published advisory PMASA-2012-5 on 25 September 2012 and rated it critical.

The advisory names the mirror cdnetworks-kr-1. The advisory says two files differ. The new file server_sync.php contains a backdoor for remote PHP code execution. The file js/cross_framing_protection.js was also modified. The advisory credits the Tencent Security Response Center for the report.

The GitHub advisory describes the new file as an eval injection. A remote attacker can run any PHP code. Exploit-DB explains the trigger. An attacker sends an HTTP POST request to server_sync.php with a parameter named c that holds the payload as hex. No login is needed. Exploit-DB lists a public exploit that appeared on 10 October 2012.

Affected versions

Indicators of compromise

How to check

You can search the web root for the backdoor file. Run this command and change the path to your own web root. It only reads files.

find /var/www -name server_sync.php

You can also search the web server logs for requests to the file.

grep "server_sync.php" /var/log/apache2/access.log*

Any result for the file means the install came from the bad zip. A log entry with a POST request means that someone used it. The log path is an example. Use the path of your server.

What to do now

  1. Search for server_sync.php in every phpMyAdmin install.
  2. If the file exists, download phpMyAdmin again from a trusted mirror. This is the fix that the advisory gives.
  3. Delete the old install folder. Do not delete only the one file, because js/cross_framing_protection.js was also changed.
  4. Check the web server logs for POST requests to the file. If you find any, treat the server as compromised. Run a full review of the server and rotate database and server credentials.
  5. Check the downloaded checksum or signature against the official release before you install.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old phpMyAdmin-prev --new phpMyAdmin-current
files scanned: 81

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    server_sync.php
           It now downloads from the internet and runs other programs. It did not before.

Frequently asked questions

Which phpMyAdmin version had the backdoor?

phpMyAdmin 3.5.2.2, only the file phpMyAdmin-3.5.2.2-all-languages.zip from the cdnetworks-kr-1 SourceForge mirror. The flaw is CVE-2012-5159.

How do I know if my phpMyAdmin install has the backdoor?

Look for a file named server_sync.php in the phpMyAdmin folder. The genuine release does not have it. If the file exists, download phpMyAdmin again from a trusted mirror.

What does the server_sync.php backdoor do?

It runs PHP code that a remote attacker sends in an HTTP POST request. The request carries a parameter named c with the payload as hex. No login is needed.

Sources

  1. phpmyadmin.net/security/PMASA-2012-5/
  2. github.com/advisories/GHSA-g39j-4qc9-5rh4
  3. exploit-db.com/exploits/21834

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free