Vulnerability Name: | CVE-2006-2418 (CCN-26441) | ||||||||||||
Assigned: | 2006-05-12 | ||||||||||||
Published: | 2006-05-12 | ||||||||||||
Updated: | 2017-07-20 | ||||||||||||
Summary: | Cross-site scripting (XSS) vulnerabilities in certain versions of phpMyAdmin before 2.8.0.4 allow remote attackers to inject arbitrary web script or HTML via the db parameter in unknown scripts. Some releases of phpMyAdmin before 2.8.0.4 are affected (2.6.2 tested vulnerable). This vulnerability is addressed in the following product release: phpMyAdmin, phpMyAdmin, 2.8.0.4 | ||||||||||||
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2006-2418 Source: SUSE Type: Patch SUSE-SR:2006:013 Source: CCN Type: SA20113 phpMyAdmin "theme" and "db" Cross-Site Scripting Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 20113 Source: SECUNIA Type: Patch, Vendor Advisory 20627 Source: SECUNIA Type: Patch, Vendor Advisory 22781 Source: DEBIAN Type: Patch, Vendor Advisory DSA-1207 Source: DEBIAN Type: DSA-1207 phpmyadmin -- several vulnerabilities Source: CCN Type: OSVDB ID: 25563 phpMyAdmin db Parameter XSS Source: CCN Type: The phpMyAdmin Project Web site phpMyAdmin - 2.8.0.3 Source: CCN Type: phpMyAdmin security announcement PMASA-2006-2 XSS vulnerabilities Source: CONFIRM Type: Patch, Vendor Advisory http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2006-2 Source: BID Type: Patch 17973 Source: CCN Type: BID-17973 phpMyAdmin Index.PHP Multiple Cross-Site Scripting Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2006-1794 Source: XF Type: UNKNOWN phpmyadmin-db-xss(26441) Source: XF Type: UNKNOWN phpmyadmin-db-xss(26441) Source: SUSE Type: SUSE-SR:2006:013 SUSE Security Summary Report | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |