CVE-2006-2753
Advisory lineage Upstream: 0 Downstream: 2
Downstream
Modified
Published: 01 Jun 2006, 17:00
Last modified:07 Aug 2024, 17:58
Vulnerability Summary
Overall Risk (default)
medium
31/100 CVSS Score
7.5 HIGH
v2.0 (nvd)
EPSS Score
6.08% LOW
6% probability -0.91%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
01 Jun 2006, 17:00
Published
Vulnerability first disclosed
07 Aug 2024, 17:58
Last Modified
Vulnerability information updated
Description
SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodings in character sets such as SJIS, BIG5, and GBK, which are not properly handled when the mysql_real_escape function is used to escape the input.
CVSS Metrics
- v2.0•HIGH•Score: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS Trends
Current EPSS score: 6.08%• Percentile: 91%
Affected Systems
- mysql•mysql
4.1.0 | 4.1.2 | 4.1.3 | 4.1.8 | 4.1.10 | 4.1.12 | 4.1.13 | 4.1.14 | 4.1.15 | 5.0.0 | 5.0.1 | 5.0.2 | 5.0.3 | 5.0.4 | 5.0.5 | 5.0.10 | 5.0.15 | 5.0.16 | 5.0.17 | 5.0.20
- oracle•mysql
4.1.1 | 4.1.4 | 4.1.5 | 4.1.6 | 4.1.7 | 4.1.9 | 4.1.11 | 4.1.16 | 4.1.17 | 4.1.18 | 4.1.19 | 5.0.6 | 5.0.7 | 5.0.8 | 5.0.9 | 5.0.11 | 5.0.12 | 5.0.13 | 5.0.14 | 5.0.18 | 5.0.19 | 5.0.21
References (26)
- http://www.debian.org/security/2006/dsa-1092
- http://lists.mysql.com/announce/364
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26875
- http://secunia.com/advisories/20712
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:097
- http://secunia.com/advisories/20541
- http://www.us-cert.gov/cas/techalerts/TA07-072A.html
- http://secunia.com/advisories/20562
- http://www.trustix.org/errata/2006/0034/
- http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html
- http://docs.info.apple.com/article.html?artnum=305214
- http://www.gentoo.org/security/en/glsa/glsa-200606-13.xml
- http://secunia.com/advisories/20365
- http://secunia.com/advisories/20531
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10312
- http://www.vupen.com/english/advisories/2006/2105
- http://www.securityfocus.com/bid/18219
- http://secunia.com/advisories/20489
- http://securitytracker.com/id?1016216
- https://usn.ubuntu.com/303-1/
- http://www.vupen.com/english/advisories/2007/0930
- http://www.ubuntu.com/usn/usn-288-3
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=369735
- http://secunia.com/advisories/20625
- http://www.redhat.com/support/errata/RHSA-2006-0544.html
- http://secunia.com/advisories/24479