CVE-2006-2753
SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodings in character sets such as SJIS, BIG5, and GBK, which are not properly…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.54%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodings in character sets such as SJIS, BIG5, and GBK, which are not properly handled when the mysql_real_escape function is used to escape the input.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 3.54% probability · 89th percentile
- CISA KEV
- Not listed
- Affected
- mysql/mysql · oracle/mysql
- Source
- secalert@redhat.com
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=369735
- http://docs.info.apple.com/article.html?artnum=305214
- http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html
- http://lists.mysql.com/announce/364Patch
- http://secunia.com/advisories/20365
- http://secunia.com/advisories/20489
- http://secunia.com/advisories/20531
- http://secunia.com/advisories/20541
- http://secunia.com/advisories/20562
- http://secunia.com/advisories/20625
- http://secunia.com/advisories/20712
- http://secunia.com/advisories/24479
- http://securitytracker.com/id?1016216
- http://www.debian.org/security/2006/dsa-1092
- http://www.gentoo.org/security/en/glsa/glsa-200606-13.xml
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:097
- http://www.redhat.com/support/errata/RHSA-2006-0544.html
- http://www.securityfocus.com/bid/18219
- http://www.trustix.org/errata/2006/0034/
- http://www.ubuntu.com/usn/usn-288-3
- http://www.us-cert.gov/cas/techalerts/TA07-072A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2006/2105
- http://www.vupen.com/english/advisories/2007/0930
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26875
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10312
- https://usn.ubuntu.com/303-1/
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=369735
- http://docs.info.apple.com/article.html?artnum=305214
- http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html
- http://lists.mysql.com/announce/364Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.