CVE-2006-6944: High severity phpMyAdmin phpMyAdmin vulnerability
Published Jan 19, 2007
·Updated
phpMyAdmin before 2.9.1.1 allows remote attackers to bypass Allow/Deny access rules that use IP addresses via false headers.
Affected Software
9 affected components
phpMyAdmin phpMyAdmin<=2.9.1
phpMyAdmin phpMyAdmin=2.9.0
phpMyAdmin phpMyAdmin=2.9.0.1
phpMyAdmin phpMyAdmin=2.9.0.2
phpMyAdmin phpMyAdmin=2.9.0.3
phpMyAdmin phpMyAdmin=2.9.0_beta1
phpMyAdmin phpMyAdmin=2.9.0_rc1
phpMyAdmin phpMyAdmin=2.9.1_rc1
phpMyAdmin phpMyAdmin=2.9.1_rc2
Remediation
Event History
Jan 19, 2007
CVE Published
02:28 AM
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-6944?
CVE-2006-6944 is classified as a medium severity vulnerability that allows remote attackers to bypass access control rules.
2
How do I fix CVE-2006-6944?
To fix CVE-2006-6944, upgrade phpMyAdmin to version 2.9.1.1 or later.
3
What versions of phpMyAdmin are affected by CVE-2006-6944?
CVE-2006-6944 affects phpMyAdmin versions prior to 2.9.1.1.
4
What kind of attacks can be executed due to CVE-2006-6944?
CVE-2006-6944 can allow remote attackers to access restricted functions by bypassing IP-based access controls.
5
Is CVE-2006-6944 still a concern for users of phpMyAdmin?
Yes, CVE-2006-6944 remains a concern for users still running vulnerable versions of phpMyAdmin.