Vulnerabilities > CVE-2006-1804 - SQL-Injection vulnerability in PHPmyadmin 2.7.0Pl1/2.8.0.3

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
phpmyadmin
nessus

Summary

SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to execute arbitrary SQL commands via the sql_query parameter. This vulnerbability may affect earlier versions of phpMyAdmin as well.

Vulnerable Configurations

Part Description Count
Application
Phpmyadmin
2

Nessus

NASL familyFreeBSD Local Security Checks
NASL idFREEBSD_PKG_2ECD02E2E86411DAB9F400123FFE8333.NASL
descriptionphpMyAdmin security team reports : It was possible to inject arbitrary SQL commands by forcing an authenticated user to follow a crafted link. Such issue is quite common in many PHP applications and users should take care what links they follow. We consider these vulnerabilities to be quite dangerous.
last seen2020-06-01
modified2020-06-02
plugin id21577
published2006-05-22
reporterThis script is Copyright (C) 2006-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/21577
titleFreeBSD : phpmyadmin -- CSRF vulnerabilities (2ecd02e2-e864-11da-b9f4-00123ffe8333)