CVE-2006-0200: SQL Injection
Published Jan 13, 2006
·Updated
Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.
Affected Software
2 affected components
PHP PHP=5.1.1
PHP PHP=5.1.0
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jan 13, 2006
CVE Published
11:03 PM
Jan 14, 2006
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0200?
CVE-2006-0200 is classified as a critical severity vulnerability due to its potential to allow remote attackers to execute arbitrary code.
2
How do I fix CVE-2006-0200?
To fix CVE-2006-0200, upgrade PHP to version 5.1.2 or later, which addresses the format string vulnerability.
3
What versions of PHP are affected by CVE-2006-0200?
CVE-2006-0200 affects PHP versions 5.1.0 and 5.1.1.
4
What type of vulnerability is CVE-2006-0200?
CVE-2006-0200 is a format string vulnerability related to the mysqli extension in PHP.
5
Can CVE-2006-0200 be exploited remotely?
Yes, CVE-2006-0200 can be exploited remotely through crafted MySQL error messages.