CVE-2006-0806

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
21/02/2006
Last modified:
03/04/2025

Description

Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbitrary web script or HTML via (1) the next_page parameter in adodb-pager.inc.php and (2) other unspecified vectors related to PHP_SELF.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:john_lim:adodb:4.66:*:*:*:*:*:*:*
cpe:2.3:a:john_lim:adodb:4.68:*:*:*:*:*:*:*
cpe:2.3:a:john_lim:adodb:4.70:*:*:*:*:*:*:*
cpe:2.3:a:john_lim:adodb:4.71:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools