CVE-2006-2418

NameCVE-2006-2418
DescriptionCross-site scripting (XSS) vulnerabilities in certain versions of phpMyAdmin before 2.8.0.4 allow remote attackers to inject arbitrary web script or HTML via the db parameter in unknown scripts.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-1207-1
NVD severitymedium (attack range: remote)
Debian Bugs368082
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
phpmyadmin (PTS)squeeze (security), squeeze4:3.3.7-7fixed
squeeze (lts)4:3.3.7-8fixed
wheezy, wheezy (security)4:3.4.11.1-2+deb7u1fixed
jessie, sid4:4.2.12-2fixed

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
phpmyadminsource(unstable)4:2.8.1-1medium368082
phpmyadminsourcesarge4:2.6.2-3sarge2mediumDSA-1207-1

Search for package or bug name: Reporting problems