First published: Sat Nov 04 2006(Updated: )
Cross-site scripting (XSS) vulnerability in error.php in phpMyAdmin 2.6.4 through 2.9.0.2 allows remote attackers to inject arbitrary web script or HTML via UTF-7 or US-ASCII encoded characters, which are injected into an error message, as demonstrated by a request with a utf7 charset parameter accompanied by UTF-7 data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PhpMyAdmin | =2.6.4_rc1 | |
PhpMyAdmin | =2.8.3 | |
PhpMyAdmin | =2.7_pl1 | |
PhpMyAdmin | =2.6.4_pl1 | |
PhpMyAdmin | =2.9 | |
PhpMyAdmin | =2.8.2 | |
PhpMyAdmin | =2.9.2 | |
PhpMyAdmin | =2.9_rc1 | |
PhpMyAdmin | =2.6.4_pl3 | |
PhpMyAdmin | =2.9.1 | |
PhpMyAdmin | =2.6.4_pl4 | |
PhpMyAdmin | =2.8.1 | |
PhpMyAdmin | =2.7.0_beta1 | |
PhpMyAdmin | =2.7 | |
PhpMyAdmin | =2.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5718 is classified as a medium severity cross-site scripting vulnerability.
To fix CVE-2006-5718, upgrade phpMyAdmin to version 2.9.0.3 or later.
CVE-2006-5718 affects phpMyAdmin versions from 2.6.4 through 2.9.0.2.
CVE-2006-5718 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts.
Yes, if you are using the affected versions of phpMyAdmin without the necessary updates, you are at risk of exploitation.