Lucene search

K
cve[email protected]CVE-2008-4456
HistoryOct 06, 2008 - 11:25 p.m.

CVE-2008-4456

2008-10-0623:25:50
CWE-79
web.nvd.nist.gov
57
cve-2008-4456
xss
mysql 5.0
command-line client
security vulnerability

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

8 High

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.0%

Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option is enabled, allows attackers to inject arbitrary web script or HTML by placing it in a database cell, which might be accessed by this client when composing an HTML document. NOTE: as of 20081031, the issue has not been fixed in MySQL 5.0.67.

Affected configurations

NVD
Node
mysqlmysqlMatch5.0.4
OR
mysqlmysqlMatch5.0.30
OR
mysqlmysqlMatch5.0.36
OR
mysqlmysqlMatch5.0.44
OR
oraclemysqlMatch5.0.26
OR
oraclemysqlMatch5.0.27
OR
oraclemysqlMatch5.0.30sp1
OR
oraclemysqlMatch5.0.32
OR
oraclemysqlMatch5.0.33
OR
oraclemysqlMatch5.0.37
OR
oraclemysqlMatch5.0.38
OR
oraclemysqlMatch5.0.41
OR
oraclemysqlMatch5.0.42
OR
oraclemysqlMatch5.0.45
OR
oraclemysqlMatch5.0.67

References

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

8 High

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.0%