CVE-2006-6942

UnknownEPSS 3.19%

Last modified

CVE-2006-6942 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1) a comment for a table name, as exploited through (a) db_operations.php, (2) the db parameter to (b) db_create.php, (3) the newname parameter to db_operations.php, the (4) query_history_latest, (5) query_history_latest_db, and (6) querydisplay_tab parameters to (c) querywindow.php, and (7) the pos parameter to (d) sql.php.. EPSS estimates a 3.19% chance of exploitation in the next 30 days.

Description

Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1) a comment for a table name, as exploited through (a) db_operations.php, (2) the db parameter to (b) db_create.php, (3) the newname parameter to db_operations.php, the (4) query_history_latest, (5) query_history_latest_db, and (6) querydisplay_tab parameters to (c) querywindow.php, and (7) the pos parameter to (d) sql.php.

Metrics

EPSS Probability
3.19%

86.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
PhpmyadminPhpmyadmin<= 2.9.1
PhpmyadminPhpmyadmin2.9.0
PhpmyadminPhpmyadmin2.9.0.1
PhpmyadminPhpmyadmin2.9.0.2
PhpmyadminPhpmyadmin2.9.0.3
PhpmyadminPhpmyadmin2.9.0_beta1
PhpmyadminPhpmyadmin2.9.0_rc1
PhpmyadminPhpmyadmin2.9.1_rc1
PhpmyadminPhpmyadmin2.9.1_rc2
DebianDebian Linux3.1
DebianDebian Linux4.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2006-6942?
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1) a comment for a table name, as exploited through (a) db_operations.php, (2) the db parameter to (b) db_create.php, (3) the newname parameter to db_operations.php, the (4) query_history_latest, (5) query_history_latest_db, and (6) querydisplay_tab parameters to (c) querywindow.php, and (7) the pos parameter to (d) sql.php.
How severe is CVE-2006-6942?
Severity scoring for CVE-2006-6942 is pending analysis. The EPSS model estimates a 3.19% probability of exploitation in the next 30 days.
How do I fix CVE-2006-6942?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2006-6942?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST