PT-2006-6887 · Phpmyadmin+1 · Phpmyadmin+1
Vincent Audet Menard
·
Published
2006-12-04
·
Updated
2018-10-17
·
CVE-2006-6258
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
AlternC versions 0.9.5 and earlier
Description
The issue concerns the transmission of the SQL password in cleartext within a cookie by the phpmyadmin subsystem. This could potentially allow remote attackers to obtain the password through sniffing or by exploiting a cross-site scripting (XSS) attack.
Recommendations
For AlternC versions 0.9.5 and earlier, consider disabling the phpmyadmin subsystem until a secure version is available. Restrict access to sensitive areas of the application to minimize the risk of exploitation. Avoid using the affected subsystem in insecure networks to reduce the risk of password sniffing.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alternc
Phpmyadmin