CVE-2006-2418: XSS
Published May 16, 2006
·Updated
Cross-site scripting (XSS) vulnerabilities in certain versions of phpMyAdmin before 2.8.0.4 allow remote attackers to inject arbitrary web script or HTML via the db parameter in unknown scripts.
Affected Software
2 affected componentsFixes available
debian/phpmyadmin
4:5.0.4+dfsg2-2+deb11u14:5.2.1+dfsg-1
phpMyAdmin phpMyAdmin=2.8.0.3
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
May 16, 2006
CVE Published
10:02 AM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2418?
CVE-2006-2418 is classified as a medium severity vulnerability, as it allows for cross-site scripting attacks.
2
How do I fix CVE-2006-2418?
To fix CVE-2006-2418, upgrade phpMyAdmin to version 2.8.0.4 or later.
3
Which versions are affected by CVE-2006-2418?
CVE-2006-2418 affects phpMyAdmin versions before 2.8.0.4.
4
What are the potential impacts of exploiting CVE-2006-2418?
Exploitation of CVE-2006-2418 can lead to unauthorized script execution in the context of the user’s session.
5
Who is the typical attacker for CVE-2006-2418?
The typical attacker for CVE-2006-2418 is a remote individual leveraging cross-site scripting techniques to manipulate user interactions.