CVE-2006-5718: XSS
Cross-site scripting (XSS) vulnerability in error.php in phpMyAdmin 2.6.4 through 2.9.0.2 allows remote attackers to inject arbitrary web script or HTML via UTF-7 or US-ASCII encoded characters, which are injected into an error message, as demonstrated by a request with a utf7 charset parameter accompanied by UTF-7 data.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5718?
CVE-2006-5718 is classified as a medium severity cross-site scripting vulnerability.
How do I fix CVE-2006-5718?
To fix CVE-2006-5718, upgrade phpMyAdmin to version 2.9.0.3 or later.
Which versions of phpMyAdmin are affected by CVE-2006-5718?
CVE-2006-5718 affects phpMyAdmin versions from 2.6.4 through 2.9.0.2.
What type of vulnerability is CVE-2006-5718?
CVE-2006-5718 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts.
Can I be exploited using CVE-2006-5718?
Yes, if you are using the affected versions of phpMyAdmin without the necessary updates, you are at risk of exploitation.