Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44172

Опубликовано: 12 июн. 2026
Источник: redhat
CVSS3: 9.1
EPSS Низкий

Описание

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.

A flaw was found in MariaDB server. An application processing non-validated user input, which then uses mysql_real_escape_string() and sends data to the database via text protocol with the big5 character set, is vulnerable to SQL injection. This allows a remote attacker to execute malicious SQL commands, potentially leading to unauthorized data access or modification within the database.

Отчет

This is an Important SQL injection vulnerability in MariaDB server affecting applications that utilize mysql_real_escape_string() with non-validated user input and the big5 character set. Exploitation allows a remote attacker to execute arbitrary SQL commands, potentially compromising data integrity and confidentiality within the database. The specific configuration required for exploitation limits its widespread impact, but systems configured in this manner are at significant risk.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10mariadb10.11Not affected
Red Hat Enterprise Linux 10mariadb11.8Not affected
Red Hat Enterprise Linux 7mariadbNot affected
Red Hat Enterprise Linux 8mariadb:10.11/mariadbNot affected
Red Hat Enterprise Linux 8mariadb:10.3/mariadbNot affected
Red Hat Enterprise Linux 8mariadb-connector-cNot affected
Red Hat Enterprise Linux 9mariadbNot affected
Red Hat Enterprise Linux 9mariadb:10.11/mariadbNot affected
Red Hat Enterprise Linux 9mariadb:11.8/mariadbNot affected
Red Hat Enterprise Linux 9mariadb-connector-cNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-89
https://bugzilla.redhat.com/show_bug.cgi?id=2488459mariadb: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string()

EPSS

Процентиль: 44%
0.00577
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.

CVSS3: 9.1
nvd
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.

CVSS3: 9.1
debian
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. In versi ...

suse-cvrf
9 дней назад

Security update for mariadb-connector-c

suse-cvrf
11 дней назад

Security update for mariadb-connector-c

EPSS

Процентиль: 44%
0.00577
Низкий

9.1 Critical

CVSS3