Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Josh Berkus

#38858de 56,330
7.5CVSS total
Vulnerabilidades · 1
PT-2006-3673
7.5
2006-06-01
Oracle · Mysql Server · CVE-2006-2753
**Name of the Vulnerable Software and Affected Versions** MySQL versions 4.1.x through 4.1.19 MySQL versions 5.0.x through 5.0.21 **Description** A SQL injection issue allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodings in character sets such as SJIS, BIG5, and GBK. The issue arises because these character sets are not properly handled when the `mysql real escape` function is used to escape the input. **Recommendations** For MySQL versions 4.1.x through 4.1.19, update to version 4.1.20 or later. For MySQL versions 5.0.x through 5.0.21, update to version 5.0.22 or later.