Secunia Logo
 
CVE Reference: CVE-2006-0806
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-0806

Description:
Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbitrary web script or HTML via (1) the next_page parameter in adodb-pager.inc.php and (2) other unspecified vectors related to PHP_SELF.

CVE Status:
Candidate

References:

SREASON
  http://securityreason.com/securityalert/452

SAID
  Secunia Advisory: SA18928
  Secunia Advisory: SA19555
  Secunia Advisory: SA19590
  Secunia Advisory: SA19591
  Secunia Advisory: SA19691

OSVDB
  23362

MISC
  http://phpesp.cvs.sourceforge.net/phpesp/phpESP/admin/include/lib/adodb/adodb-pager.inc.php?r1=1.1&r2=1.2
  http://www.gulftech.org/?node=research&article_id=00101-02182006

GENTOO
  http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml

DEBIAN
  http://www.debian.org/security/2006/dsa-1031
  http://www.debian.org/security/2006/dsa-1030
  http://www.debian.org/security/2006/dsa-1029

CONFIRM
  http://sourceforge.net/project/shownotes.php?release_id=419843&group_id=8956

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/425393/100/0/threaded

BID
  16720


Return to the previous page.