A AegiFlow
HIGHCVSS 9.3

CVE-2006-0200

CVE-2006-0200 updated by NVD

Modified
2026-09-20
Sources
nvd

Summary

Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.

Affected packages

EcosystemPackageAffected versionsFixed versions
PHPphp[object Object], [object Object]

References

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.