Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option is enabled, allows attackers to inject arbitrary web script or HTML by placing it in a database cell, which might be accessed by this client when composing an HTML document. NOTE: as of 20081031, the issue has not been fixed in MySQL 5.0.67.
CVSS Details
- CVSS 3.1 Base Score: 6.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Mysql | — | Upgrade macOS to the latest version | Dec 16, 2011 | Oct 6, 2008 |
| Centos_linux | — | Upgrade mysql-benchUpgrade mysql-develUpgrade mysql-serverUpgrade mysqlUpgrade mysql-test | Dec 1, 2016 | Oct 6, 2008 |
| Gentoo Linux | — | Upgrade dev-db/mysql. | Oct 30, 2017 | Oct 6, 2008 |
| Oracle_linux | — | Upgrade mysqlUpgrade mysql-benchUpgrade mysql-testUpgrade mysql-develUpgrade mysql-server | Oct 16, 2024 | Oct 6, 2008 |
| Suse | — | Upgrade libmysqlclient15-32bitUpgrade mysql-clientUpgrade mysqlUpgrade mysql-toolsUpgrade libmysqlclient15Upgrade mysql-MaxUpgrade libmysqlclient15-x86Upgrade libmysql55client18Upgrade libmysqlclient_r15-32bitUpgrade libmysqlclient_r15Upgrade libmysql55client_r18-32bitUpgrade libmysql55client18-x86Upgrade libmysql55client_r18-x86Upgrade libmysqlclient-develUpgrade libmysql55client18-32bitUpgrade libmysql55client_r18Upgrade libmysqlclient_r15-x86 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade mysql-server-5.1Upgrade mysql-server-5.0 | Nov 8, 2024 | Oct 6, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub