CVE-2006-0806: XSS
Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbitrary web script or HTML via (1) the nextpage parameter in adodb-pager.inc.php and (2) other unspecified vectors related to PHPSELF.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0806?
CVE-2006-0806 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2006-0806?
To fix CVE-2006-0806, upgrade ADOdb to version 4.72 or later, which addresses the XSS vulnerabilities.
What software versions are affected by CVE-2006-0806?
CVE-2006-0806 affects ADOdb versions 4.66, 4.68, 4.70, and 4.71.
Can CVE-2006-0806 be exploited remotely?
Yes, CVE-2006-0806 can be exploited remotely by injecting malicious scripts through vulnerable input parameters.
What types of attacks can occur due to CVE-2006-0806?
CVE-2006-0806 can lead to cross-site scripting (XSS) attacks, allowing attackers to execute arbitrary scripts in users' browsers.