CVE-2006-2753

Advisory lineage Upstream: 0 Downstream: 2
Modified
Published: 01 Jun 2006, 17:00
Last modified:07 Aug 2024, 17:58

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.5 HIGH
v2.0 (nvd)
EPSS Score
6.08% LOW
6% probability -0.91%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

01 Jun 2006, 17:00
Published
Vulnerability first disclosed
07 Aug 2024, 17:58
Last Modified
Vulnerability information updated

Description

SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodings in character sets such as SJIS, BIG5, and GBK, which are not properly handled when the mysql_real_escape function is used to escape the input.

CVSS Metrics

  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 6.08% Percentile: 91%

Affected Systems

  • mysqlmysql

    4.1.0 | 4.1.2 | 4.1.3 | 4.1.8 | 4.1.10 | 4.1.12 | 4.1.13 | 4.1.14 | 4.1.15 | 5.0.0 | 5.0.1 | 5.0.2 | 5.0.3 | 5.0.4 | 5.0.5 | 5.0.10 | 5.0.15 | 5.0.16 | 5.0.17 | 5.0.20

  • oraclemysql

    4.1.1 | 4.1.4 | 4.1.5 | 4.1.6 | 4.1.7 | 4.1.9 | 4.1.11 | 4.1.16 | 4.1.17 | 4.1.18 | 4.1.19 | 5.0.6 | 5.0.7 | 5.0.8 | 5.0.9 | 5.0.11 | 5.0.12 | 5.0.13 | 5.0.14 | 5.0.18 | 5.0.19 | 5.0.21

References (26)