Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-9244

Опубликовано: 29 мая 2018
Источник: debian

Описание

Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-mysqlfixed2.0.0~alpha8-1package

Примечания

  • https://github.com/felixge/node-mysql/issues/342

  • https://nodesecurity.io/advisories/66

  • nodejs not covered by security support

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection.

CVSS3: 9.8
nvd
больше 7 лет назад

Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection.

github
больше 5 лет назад

SQL Injection in mysql