Vulnerability Name: | CVE-2006-1804 (CCN-25858) | ||||||||||||||||
Assigned: | 2006-04-12 | ||||||||||||||||
Published: | 2006-04-12 | ||||||||||||||||
Updated: | 2018-10-18 | ||||||||||||||||
Summary: | SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to execute arbitrary SQL commands via the sql_query parameter. This vulnerbability may affect earlier versions of phpMyAdmin as well. | ||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||||||||||
References: | Source: CCN Type: BugTraq Mailing List, Wed Apr 12 2006 - 13:50:37 CDT phpMyAdmin 2.7.0-pl1 Source: MITRE Type: CNA CVE-2006-1804 Source: CCN Type: SA19659 phpMyAdmin Cross-Site Scripting and SQL Code Execution Source: SECUNIA Type: Exploit, Vendor Advisory 19659 Source: SECUNIA Type: UNKNOWN 19897 Source: SUSE Type: UNKNOWN SUSE-SR:2006:009 Source: CCN Type: OSVDB ID: 24642 phpMyAdmin sql.php sql_query Parameter SQL Injection Source: CCN Type: The phpMyAdmin Project Web site phpMyAdmin - 2.8.0.3 Source: BUGTRAQ Type: UNKNOWN 20060412 phpMyAdmin 2.7.0-pl1 Source: VUPEN Type: UNKNOWN ADV-2006-1372 Source: XF Type: UNKNOWN phpmyadmin-sql-sql-injection(25858) Source: XF Type: UNKNOWN phpmyadmin-sql-sql-injection(25858) Source: SUSE Type: SUSE-SR:2006:009 SUSE Security Summary Report | ||||||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |