Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-4700

Опубликовано: 18 янв. 2011
Источник: ubuntu
Приоритет: medium
CVSS2: 6.8

Описание

The set_magic_quotes_runtime function in PHP 5.3.2 and 5.3.3, when the MySQLi extension is used, does not properly interact with use of the mysqli_fetch_assoc function, which might make it easier for context-dependent attackers to conduct SQL injection attacks via crafted input that had been properly handled in earlier PHP versions.

РелизСтатусПримечание
dapper

not-affected

devel

not-affected

5.3.5-1ubuntu1
hardy

not-affected

karmic

not-affected

lucid

not-affected

maverick

not-affected

upstream

released

5.3.4

Показывать по

Ссылки на источники

6.8 Medium

CVSS2

Связанные уязвимости

redhat
около 15 лет назад

The set_magic_quotes_runtime function in PHP 5.3.2 and 5.3.3, when the MySQLi extension is used, does not properly interact with use of the mysqli_fetch_assoc function, which might make it easier for context-dependent attackers to conduct SQL injection attacks via crafted input that had been properly handled in earlier PHP versions.

nvd
больше 14 лет назад

The set_magic_quotes_runtime function in PHP 5.3.2 and 5.3.3, when the MySQLi extension is used, does not properly interact with use of the mysqli_fetch_assoc function, which might make it easier for context-dependent attackers to conduct SQL injection attacks via crafted input that had been properly handled in earlier PHP versions.

debian
больше 14 лет назад

The set_magic_quotes_runtime function in PHP 5.3.2 and 5.3.3, when the ...

github
больше 3 лет назад

The set_magic_quotes_runtime function in PHP 5.3.2 and 5.3.3, when the MySQLi extension is used, does not properly interact with use of the mysqli_fetch_assoc function, which might make it easier for context-dependent attackers to conduct SQL injection attacks via crafted input that had been properly handled in earlier PHP versions.

6.8 Medium

CVSS2