Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2012-0369

Опубликовано: 07 мар. 2012
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2012-0369: python-sqlalchemy security update (MODERATE)

[0.5.5-3]

  • sanitize inputs to limit() and offset() Resolves: CVE-2012-0805

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

python-sqlalchemy

0.5.5-3.el6_2

Oracle Linux i686

python-sqlalchemy

0.5.5-3.el6_2

Oracle Linux sparc64

python-sqlalchemy

0.5.5-3.el6_2

Связанные CVE

Связанные уязвимости

ubuntu
около 13 лет назад

Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, as used in Keystone, allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset keyword to the select function, or unspecified vectors to the (3) select.limit or (4) select.offset function.

redhat
больше 13 лет назад

Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, as used in Keystone, allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset keyword to the select function, or unspecified vectors to the (3) select.limit or (4) select.offset function.

nvd
около 13 лет назад

Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, as used in Keystone, allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset keyword to the select function, or unspecified vectors to the (3) select.limit or (4) select.offset function.

debian
около 13 лет назад

Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, a ...

CVSS3: 9.8
github
больше 3 лет назад

SQLAlchemy vulnerable to SQL injection