---
title: "CVE-2006-0208\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2006-0208?format=md
keywords: index, follow
---

# CVE-2006-0208

Publication date 13 January 2006

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1,
when display\_errors and html\_errors are on, allow remote attackers to
inject arbitrary web script or HTML via inputs to PHP applications that are
not filtered when they are included in the resulting error message.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| php4 | 7.04 feisty | Not in release |
| 6.10 edgy | Fixed 4.4.2-1build1 |
| 6.06 LTS dapper | Fixed 4.4.2-1build1 |
| php5 | 7.04 feisty | Fixed 5.2.1-0ubuntu1.4 |
| 6.10 edgy | Fixed 5.1.6-1ubuntu2.6 |
| 6.06 LTS dapper | Fixed 5.1.2-1ubuntu3.9 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0208)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2006-0208)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2006-0208)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2006-0208)

### Related Ubuntu Security Notices (USN)

+ [USN-261-1](https://usn.ubuntu.com/USN-261-1)
+ PHP vulnerabilities
+ 10 March 2006

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2006-0208>
