CVE-2006-1804: SQL Injection
Published Apr 18, 2006
·Updated
SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to execute arbitrary SQL commands via the sqlquery parameter.
Affected Software
3 affected componentsFixes available
debian/phpmyadmin
4:5.0.4+dfsg2-2+deb11u14:5.2.1+dfsg-1
phpMyAdmin phpMyAdmin=2.7.0_pl1
phpMyAdmin phpMyAdmin=2.8.0.3
Event History
Apr 18, 2006
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1804?
CVE-2006-1804 has a medium severity rating due to its potential for unauthorized access and manipulation of the database.
2
How do I fix CVE-2006-1804?
To fix CVE-2006-1804, upgrade to a patched version of phpMyAdmin, specifically versions later than 2.8.0.3.
3
What software is affected by CVE-2006-1804?
CVE-2006-1804 affects phpMyAdmin versions 2.7.0-pl1 and 2.8.0.3.
4
What type of vulnerability is CVE-2006-1804?
CVE-2006-1804 is classified as an SQL injection vulnerability.
5
Can CVE-2006-1804 be exploited remotely?
Yes, CVE-2006-1804 can be exploited remotely allowing attackers to execute arbitrary SQL commands.