4.3
CVSSv2

CVE-2006-2417

Published: 16/05/2006 Updated: 20/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.x prior to 2.8.0.4 allows remote malicious users to inject arbitrary web script or HTML via the theme parameter in unknown scripts. NOTE: the lang parameter is already covered by CVE-2006-2031.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 2.8.0.1

phpmyadmin phpmyadmin 2.8.0.2

phpmyadmin phpmyadmin 2.8.0.3

Vendor Advisories

Debian Bug report logs - #368082 phpmyadmin: CVE-2006-2417 and CVE-2006-2418: XSS Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Alec Berryman <alec@thenednet> Date: Fri, 19 May 2006 18:48:05 UTC Severi ...
Debian Bug report logs - #339437 HTTP Response Splitting vulnerability Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Michal Čihař <michal@ciharcom> Date: Wed, 16 Nov 2005 10:33:02 UTC Severity: grave ...
Debian Bug report logs - #362567 CVE-2006-1678: Multiple cross-site scripting (XSS) vulnerabilities Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Fri, 14 Apr 2006 09 ...
Debian Bug report logs - #340438 CVE-2005-3665: Cross-site scripting by trusting potentially user-supplied input Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Piotr Roszatycki <Piotr_Roszatycki@netianetpl& ...