Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-1208

Опубликовано: 01 апр. 2009
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5

Описание

SQL injection vulnerability in auth2db 0.2.5, and possibly other versions before 0.2.7, uses the addslashes function instead of the mysql_real_escape_string function, which allows remote attackers to conduct SQL injection attacks using multibyte character encodings.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

gutsy

DNE

hardy

DNE

intrepid

ignored

end of life, was needed
jaunty

ignored

end of life
karmic

not-affected

0.2.5-2+dfsg-1.1ubuntu1
lucid

not-affected

maverick

not-affected

upstream

released

0.2.5-2+dfsg-1.1

Показывать по

Ссылки на источники

EPSS

Процентиль: 69%
0.00605
Низкий

7.5 High

CVSS2

Связанные уязвимости

nvd
больше 16 лет назад

SQL injection vulnerability in auth2db 0.2.5, and possibly other versions before 0.2.7, uses the addslashes function instead of the mysql_real_escape_string function, which allows remote attackers to conduct SQL injection attacks using multibyte character encodings.

debian
больше 16 лет назад

SQL injection vulnerability in auth2db 0.2.5, and possibly other versi ...

github
больше 3 лет назад

SQL injection vulnerability in auth2db 0.2.5, and possibly other versions before 0.2.7, uses the addslashes function instead of the mysql_real_escape_string function, which allows remote attackers to conduct SQL injection attacks using multibyte character encodings.

EPSS

Процентиль: 69%
0.00605
Низкий

7.5 High

CVSS2