Описание
MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.
A flaw was found in MariaDB server. An application processing non-validated user input, which then uses mysql_real_escape_string() and sends data to the database via text protocol with the big5 character set, is vulnerable to SQL injection. This allows a remote attacker to execute malicious SQL commands, potentially leading to unauthorized data access or modification within the database.
Отчет
This is an Important SQL injection vulnerability in MariaDB server affecting applications that utilize mysql_real_escape_string() with non-validated user input and the big5 character set. Exploitation allows a remote attacker to execute arbitrary SQL commands, potentially compromising data integrity and confidentiality within the database. The specific configuration required for exploitation limits its widespread impact, but systems configured in this manner are at significant risk.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | mariadb10.11 | Not affected | ||
| Red Hat Enterprise Linux 10 | mariadb11.8 | Not affected | ||
| Red Hat Enterprise Linux 7 | mariadb | Not affected | ||
| Red Hat Enterprise Linux 8 | mariadb:10.11/mariadb | Not affected | ||
| Red Hat Enterprise Linux 8 | mariadb:10.3/mariadb | Not affected | ||
| Red Hat Enterprise Linux 8 | mariadb-connector-c | Not affected | ||
| Red Hat Enterprise Linux 9 | mariadb | Not affected | ||
| Red Hat Enterprise Linux 9 | mariadb:10.11/mariadb | Not affected | ||
| Red Hat Enterprise Linux 9 | mariadb:11.8/mariadb | Not affected | ||
| Red Hat Enterprise Linux 9 | mariadb-connector-c | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
9.1 Critical
CVSS3
Связанные уязвимости
MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.
MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.
MariaDB server is a community developed fork of MySQL server. In versi ...
EPSS
9.1 Critical
CVSS3