SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodings in character sets such as SJIS, BIG5, and GBK, which are not properly handled when the mysql_real_escape function is used to escape the input.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Mysqlserver | — | Upgrade macOS to the latest version | Dec 16, 2011 | Jun 1, 2006 |
| Gentoo Linux | — | Upgrade dev-db/mysql. | Oct 30, 2017 | Jun 1, 2006 |
| Ubuntu | — | Upgrade exim4-daemon-heavyUpgrade mysql-server-5.0Upgrade dovecot-commonUpgrade libmysqlclient15offUpgrade libmysqlclient14Upgrade mysql-server-4.1Upgrade postfix-pgsql | Nov 8, 2024 | Jun 1, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub