Full title: phpMyAdmin Authenticated Remote Code Execution Vulnerability Category: remote exploits Platform: php This Metasploit module exploits a PREG_REPLACE_EVAL vulnerability in phpMyAdmin's replace_prefix_tbl within libraries/mult_submits.inc.php via db_settings.php. This affects versions 3.5.x below 3.5.8.1 and 4.0.0 below 4.0.0-rc3. PHP versions greater than 5.4.6 are not vulnerable. # 0day.today @ http://0day.today/