Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
phpMyAdmin-CVE-2020-5504-Exploit — Authorized SQL injection exploitation framework for CVE-2020-5504 in phpMyAdmin, featuring automated database enumeration, blind injection, proxy support, and structured reporting for penetration testing and security research. | Kitploit
Tools/GitHubGitHub/cerberusmrxi/phpmyadmin-cve-2020-5504-exploit
ReconnaissanceVulnerability ScannersExploitationWeb Application ExploitationInformation GatheringWeb SecurityPenetration TestingDatabase Security

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
cerberusmrxi/phpmyadmin-cve-2020-5504-exploit

phpMyAdmin-CVE-2020-5504-Exploit

Authorized SQL injection exploitation framework for CVE-2020-5504 in phpMyAdmin, featuring automated database enumeration, blind injection, proxy support, and structured reporting for penetration testing and security research.

View Repository
211 month agoNot yet reviewed

CVE-2020-5504 phpMyAdmin Security Assessment Tool

Authorized security testing and research framework for identifying and validating CVE-2020-5504 in phpMyAdmin deployments

VersionPythonLicenseSecurity ResearchCVEPull Requests

Overview · Features · Installation · Usage · Reports · Architecture · Contributing

Responsible-use notice: This project is intended only for systems that you own or are explicitly authorized to assess. Do not use it against public, third-party, or production systems without written permission and a defined testing scope.


Screenshots

CLI OutputUsage
CLI OutputUsage

Overview

CVE-2020-5504 is a SQL injection vulnerability affecting the phpMyAdmin user accounts page. According to the official phpMyAdmin advisory, phpMyAdmin 4.x versions before 4.9.4 and phpMyAdmin 5.0.0 are affected; the advisory recommends upgrading to 4.9.4 or newer for the 4.x line and 5.0.1 or newer for the 5.x line.[1] The National Vulnerability Database records that exploitation requires a valid MySQL account to access the server.[2]

This project provides a structured workflow for authorized penetration testing, controlled validation, and security research. It is designed to help assessors fingerprint a target, verify whether the target appears affected, document evidence, and produce structured reports for remediation tracking.

Project goals

The framework is organized around four goals:

  1. Identify phpMyAdmin installations and collect version-related indicators.

  2. Validate suspected exposure using controlled, non-destructive checks where possible.

  3. Assess authorized targets using configurable limits, retry behavior, and optional proxying.

  4. Report findings in formats that are easy to review, archive, and integrate into workflows.

What this project is not

This project is not a substitute for patching, vendor guidance, secure configuration, or a formal penetration-testing authorization process. It does not guarantee detection of every deployment, configuration, version, or network condition. All results should be manually reviewed and treated as assessment evidence rather than an automatic security verdict.


Contents

  • Overview

  • Responsible use

  • Features

  • Assessment workflow

  • Requirements

  • Installation

  • Usage

  • Operating modes

  • Command-line options

  • Configuration

  • Reports

  • Architecture

  • Troubleshooting

  • Remediation guidance

  • Development

  • Contributing

  • Changelog

  • License

  • Acknowledgments

  • Contact and support

  • References


Responsible use

Authorization is required

Only run this tool against an asset when you have clear authorization from the asset owner. Authorization should define the target, allowed test window, permitted techniques, source IPs, data-handling requirements, escalation contacts, and stop conditions.

Never test internet-facing systems merely because they are reachable. Reachability is not permission.

Data handling

Assessment modes may produce information about databases, tables, columns, or records. Treat all output as potentially sensitive. Store reports using appropriate access controls, avoid placing secrets in shell history, encrypt reports when required by your engagement rules, and securely delete temporary data after the engagement.

Operational safeguards

Before starting an assessment, confirm that you have a known-good backup or recovery procedure, a communication channel with the system owner, and a documented rollback or stop plan. Prefer an isolated test environment whenever one is available. Use the least intrusive mode that answers the assessment question.


Features

AreaCapabilityDescription
DiscoveryAutomated fingerprintingIdentifies likely phpMyAdmin deployments and gathers version indicators.
ValidationVulnerability verificationPerforms controlled checks with confidence-oriented result handling.
WorkflowMultiple operating modesSupports detection, verification, research, and dry-run workflows.
Session handlingCSRF token managementExtracts and manages CSRF-related values required by the application flow.
AuthenticationMulti-signal validationUses multiple indicators to reduce false authentication results.
AssessmentDatabase enumerationSupports authorized enumeration of databases, tables, columns, and selected data.
Injection researchBlind techniquesSupports boolean-based and time-based research workflows where enabled by the implementation.
ReportingJSON, HTML, and TXTProduces structured, styled, and plain-text output for different audiences.
ReliabilityRetries and backoffRetries transient requests with configurable behavior.
IntegrationsProxy supportCan be used with Burp Suite or another HTTP interception proxy.
UsabilityRich terminal interfaceProvides color-coded output, progress indicators, and readable status messages.
DiagnosticsVerbose loggingExposes additional diagnostic information for authorized troubleshooting.

Assessment workflow

The recommended workflow is intentionally staged so that assessors can begin with the lowest-impact activity and increase scope only when authorized.

┌──────────────────┐
│  Define scope    │  Confirm written authorization and test boundaries
└────────┬─────────┘
         │
         ▼
┌──────────────────┐
│     Detect       │  Identify phpMyAdmin and collect version indicators
└────────┬─────────┘
         │
         ▼
┌──────────────────┐
│     Verify       │  Perform controlled vulnerability checks
└────────┬─────────┘
         │
         ▼
┌──────────────────┐
│  Assess, if      │  Continue only when explicitly authorized
│  approved        │
└────────┬─────────┘
         │
         ▼
┌──────────────────┐
│     Report       │  Preserve evidence, limits, timestamps, and conclusions
└──────────────────┘

A positive result should be reviewed against the target version, authentication context, request evidence, and engagement scope. A negative result does not prove that the deployment is secure; it may reflect version differences, access controls, routing, application customization, rate limiting, or insufficient visibility.


Requirements

Runtime requirements

Download Tool