Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-2940

Опубликовано: 22 окт. 2009
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5

Описание

The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

hardy

released

1:3.8.1-2ubuntu0.1
intrepid

released

1:3.8.1-3ubuntu0.1
jaunty

not-affected

1:4.0-0ubuntu1
karmic

not-affected

upstream

released

1:4.0-1

Показывать по

EPSS

Процентиль: 72%
0.00734
Низкий

7.5 High

CVSS2

Связанные уязвимости

CVSS3: 5.4
redhat
больше 15 лет назад

The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

nvd
больше 15 лет назад

The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

debian
больше 15 лет назад

The pygresql module 3.8.1 and 4.0 for Python does not properly support ...

github
около 3 лет назад

PyGreSQL Might Be Vulnerable to Encoding-Based SQL Injection

EPSS

Процентиль: 72%
0.00734
Низкий

7.5 High

CVSS2