First published: Tue May 16 2006(Updated: )
Cross-site scripting (XSS) vulnerabilities in certain versions of phpMyAdmin before 2.8.0.4 allow remote attackers to inject arbitrary web script or HTML via the db parameter in unknown scripts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyAdmin phpMyAdmin | =2.8.0.3 | |
debian/phpmyadmin | 4:5.0.4+dfsg2-2+deb11u1 4:5.2.1+dfsg-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2418 is classified as a medium severity vulnerability, as it allows for cross-site scripting attacks.
To fix CVE-2006-2418, upgrade phpMyAdmin to version 2.8.0.4 or later.
CVE-2006-2418 affects phpMyAdmin versions before 2.8.0.4.
Exploitation of CVE-2006-2418 can lead to unauthorized script execution in the context of the user’s session.
The typical attacker for CVE-2006-2418 is a remote individual leveraging cross-site scripting techniques to manipulate user interactions.