Unrated severityNVD Advisory· Published Feb 21, 2006· Updated Apr 16, 2026
CVE-2006-0806
CVE-2006-0806
Description
Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbitrary web script or HTML via (1) the next_page parameter in adodb-pager.inc.php and (2) other unspecified vectors related to PHP_SELF.
Affected products
4Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
18- secunia.com/advisories/18928nvdVendor Advisory
- secunia.com/advisories/19555nvdVendor Advisory
- secunia.com/advisories/19590nvdVendor Advisory
- secunia.com/advisories/19591nvdVendor Advisory
- secunia.com/advisories/19691nvdVendor Advisory
- www.vupen.com/english/advisories/2006/0664nvdVendor Advisory
- www.vupen.com/english/advisories/2006/2021nvdVendor Advisory
- phpesp.cvs.sourceforge.net/phpesp/phpESP/admin/include/lib/adodb/adodb-pager.inc.phpnvd
- securityreason.com/securityalert/452nvd
- sourceforge.net/project/shownotes.phpnvd
- www.debian.org/security/2006/dsa-1029nvd
- www.debian.org/security/2006/dsa-1030nvd
- www.debian.org/security/2006/dsa-1031nvd
- www.gentoo.org/security/en/glsa/glsa-200604-07.xmlnvd
- www.gulftech.orgnvd
- www.osvdb.org/23362nvd
- www.securityfocus.com/archive/1/425393/100/0/threadednvd
- www.securityfocus.com/bid/16720nvd
News mentions
0No linked articles in our index yet.