CVE-2006-6374: CRLF Injection
Multiple CRLF injection vulnerabilities in PhpMyAdmin 2.7.0-pl2 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a phpMyAdmin cookie in (1) css/phpmyadmin.css.php, (2) dbcreate.php, (3) index.php, (4) left.php, (5) libraries/session.inc.php, (6) libraries/transformations/overview.php, (7) querywindow.php, (8) serverengines.php, and possibly other files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6374?
The severity of CVE-2006-6374 is considered high due to its potential for HTTP response splitting attacks.
How do I fix CVE-2006-6374?
To fix CVE-2006-6374, upgrade PhpMyAdmin to a version that is not affected by this vulnerability.
What systems are affected by CVE-2006-6374?
CVE-2006-6374 affects PhpMyAdmin version 2.7.0-pl2.
What types of attacks can CVE-2006-6374 lead to?
CVE-2006-6374 can lead to HTTP response splitting attacks, allowing remote attackers to inject arbitrary HTTP headers.
Is CVE-2006-6374 easy to exploit?
Yes, CVE-2006-6374 can be easily exploited by attackers familiar with CRLF injection techniques.