First published: Thu Oct 12 2006(Updated: )
Cross-site scripting (XSS) vulnerability in sql.php in MysqlDumper 1.21 b6 allows remote attackers to inject arbitrary web script or HTML via the db parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mysqldumper | =1.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5264 has a medium severity level due to its ability to enable cross-site scripting attacks.
To fix CVE-2006-5264, you should upgrade MysqlDumper to version 1.21 or later and ensure that input validation is applied to the db parameter.
CVE-2006-5264 is classified as a cross-site scripting (XSS) vulnerability.
Users of MysqlDumper version 1.21 b6 are affected by CVE-2006-5264.
Attackers exploiting CVE-2006-5264 can inject arbitrary web scripts or HTML through the db parameter.