First published: Tue Apr 18 2006(Updated: )
SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to execute arbitrary SQL commands via the sql_query parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/phpmyadmin | 4:5.0.4+dfsg2-2+deb11u1 4:5.2.1+dfsg-1 | |
phpMyAdmin | =2.7.0_pl1 | |
phpMyAdmin | =2.8.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1804 has a medium severity rating due to its potential for unauthorized access and manipulation of the database.
To fix CVE-2006-1804, upgrade to a patched version of phpMyAdmin, specifically versions later than 2.8.0.3.
CVE-2006-1804 affects phpMyAdmin versions 2.7.0-pl1 and 2.8.0.3.
CVE-2006-1804 is classified as an SQL injection vulnerability.
Yes, CVE-2006-1804 can be exploited remotely allowing attackers to execute arbitrary SQL commands.