PublicDate: 2006-05-16 10:02:00 UTC Candidate: CVE-2006-2417 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2417 Description: Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.x before 2.8.0.4 allows remote attackers to inject arbitrary web script or HTML via the theme parameter in unknown scripts. NOTE: the lang parameter is already covered by CVE-2006-2031. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_phpmyadmin: ignored (reached end-of-life) edgy_phpmyadmin: not-affected feisty_phpmyadmin: not-affected gutsy_phpmyadmin: not-affected hardy_phpmyadmin: not-affected intrepid_phpmyadmin: not-affected jaunty_phpmyadmin: not-affected karmic_phpmyadmin: not-affected devel_phpmyadmin: not-affected upstream_phpmyadmin: released (2.8.0.4)