CVE-2006-2031: XSS
Published Apr 26, 2006
·Updated
Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin 2.8.0.3, 2.8.0.2, 2.8.1-dev, and 2.9.0-dev allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
Affected Software
5 affected componentsFixes available
debian/phpmyadmin
4:5.0.4+dfsg2-2+deb11u14:5.2.1+dfsg-1
phpMyAdmin phpMyAdmin=2.8.1_dev
phpMyAdmin phpMyAdmin=2.8.0.2
phpMyAdmin phpMyAdmin=2.9.0_dev
phpMyAdmin phpMyAdmin=2.8.0.3
Event History
Apr 26, 2006
CVE Published
12:06 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2031?
CVE-2006-2031 is classified as a moderate severity cross-site scripting vulnerability.
2
How do I fix CVE-2006-2031?
To fix CVE-2006-2031, upgrade to a patched version of phpMyAdmin that is not vulnerable, such as 4:5.0.4+dfsg2-2+deb11u1 or 4:5.2.1+dfsg-1.
3
What versions of phpMyAdmin are affected by CVE-2006-2031?
CVE-2006-2031 affects phpMyAdmin versions 2.8.0.2, 2.8.0.3, 2.9.0-dev, and 2.8.1-dev.
4
What type of attack is possible due to CVE-2006-2031?
CVE-2006-2031 allows remote attackers to execute arbitrary web scripts or HTML via the lang parameter.
5
Is user input validated in phpMyAdmin versions affected by CVE-2006-2031?
No, the affected versions of phpMyAdmin do not properly validate user input, which leads to the XSS vulnerability.