PT-2006-6887 · Phpmyadmin+1 · Phpmyadmin+1

Vincent Audet Menard

·

Published

2006-12-04

·

Updated

2018-10-17

·

CVE-2006-6258

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions AlternC versions 0.9.5 and earlier
Description The issue concerns the transmission of the SQL password in cleartext within a cookie by the phpmyadmin subsystem. This could potentially allow remote attackers to obtain the password through sniffing or by exploiting a cross-site scripting (XSS) attack.
Recommendations For AlternC versions 0.9.5 and earlier, consider disabling the phpmyadmin subsystem until a secure version is available. Restrict access to sensitive areas of the application to minimize the risk of exploitation. Avoid using the affected subsystem in insecure networks to reduce the risk of password sniffing.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6258

Affected Products

Alternc
Phpmyadmin