CVE-2006-5718

See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2006-5718
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2006-5718.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2006-5718
Published
2006-11-04T01:07:00Z
Modified
2024-06-04T04:00:19Z
Summary
[none]
Details

Cross-site scripting (XSS) vulnerability in error.php in phpMyAdmin 2.6.4 through 2.9.0.2 allows remote attackers to inject arbitrary web script or HTML via UTF-7 or US-ASCII encoded characters, which are injected into an error message, as demonstrated by a request with a utf7 charset parameter accompanied by UTF-7 data.

References

Affected packages

Debian:11 / phpmyadmin

Package

Name
phpmyadmin
Purl
pkg:deb/debian/phpmyadmin?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4:2.9.0.3-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:12 / phpmyadmin

Package

Name
phpmyadmin
Purl
pkg:deb/debian/phpmyadmin?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4:2.9.0.3-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:13 / phpmyadmin

Package

Name
phpmyadmin
Purl
pkg:deb/debian/phpmyadmin?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4:2.9.0.3-1

Ecosystem specific

{
    "urgency": "low"
}