Back

CVE-2006-0200

Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.

Published: Jan 13, 2006 Modified: Jun 16, 2026
CWE-134

CVSS Metrics

Affected Products (2)

Vendor Product Version
php php 5.1.0
php php 5.1.1

GitHub Security Advisory GHSA-3qpw-mprx-xfrv

Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0...

Risk Scores

CVSS Score 9.3 / 10
EPSS Score 19.36%

Top 3% most likely to be exploited

Threat Score 43 / 100

Data Sources

NVD EPSS GitHub