Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44172

Опубликовано: 12 июн. 2026
Источник: redhat
CVSS3: 9.1

Описание

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.

A flaw was found in MariaDB server. An application processing non-validated user input, which then uses mysql_real_escape_string() and sends data to the database via text protocol with the big5 character set, is vulnerable to SQL injection. This allows a remote attacker to execute malicious SQL commands, potentially leading to unauthorized data access or modification within the database.

Отчет

This is an Important SQL injection vulnerability in MariaDB server affecting applications that utilize mysql_real_escape_string() with non-validated user input and the big5 character set. Exploitation allows a remote attacker to execute arbitrary SQL commands, potentially compromising data integrity and confidentiality within the database. The specific configuration required for exploitation limits its widespread impact, but systems configured in this manner are at significant risk.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10mariadb10.11Not affected
Red Hat Enterprise Linux 10mariadb11.8Not affected
Red Hat Enterprise Linux 7mariadbNot affected
Red Hat Enterprise Linux 8mariadb:10.11/mariadbNot affected
Red Hat Enterprise Linux 8mariadb:10.3/mariadbNot affected
Red Hat Enterprise Linux 8mariadb-connector-cAffected
Red Hat Enterprise Linux 9mariadbNot affected
Red Hat Enterprise Linux 9mariadb:10.11/mariadbNot affected
Red Hat Enterprise Linux 9mariadb:11.8/mariadbNot affected
Red Hat Enterprise Linux 9mariadb-connector-cAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-89
https://bugzilla.redhat.com/show_bug.cgi?id=2488459mariadb: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string()

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
4 месяца назад

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.

CVSS3: 9.1
nvd
4 месяца назад

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.

CVSS3: 9.1
debian
4 месяца назад

MariaDB server is a community developed fork of MySQL server. In versi ...

suse-cvrf
2 месяца назад

Security update for mariadb-connector-c

suse-cvrf
3 месяца назад

Security update for mariadb-connector-c

9.1 Critical

CVSS3