Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-44172

Опубликовано: 12 июн. 2026
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mariadb:mariadb:3.3.18:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:mariadb:3.4.8:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 44%
0.00577
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-89
CWE-89

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.

CVSS3: 9.1
redhat
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.

CVSS3: 9.1
debian
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. In versi ...

suse-cvrf
14 дней назад

Security update for mariadb-connector-c

github
2 месяца назад

mysql_real_escape_string() incorrectly handled big5

EPSS

Процентиль: 44%
0.00577
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-89
CWE-89