Lucene search

K
ubuntucveUbuntu.comUB:CVE-2006-2753
HistoryJun 01, 2006 - 12:00 a.m.

CVE-2006-2753

2006-06-0100:00:00
ubuntu.com
ubuntu.com
20

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.004

Percentile

74.7%

SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before
5.0.22 allows context-dependent attackers to execute arbitrary SQL commands
via crafted multibyte encodings in character sets such as SJIS, BIG5, and
GBK, which are not properly handled when the mysql_real_escape function is
used to escape the input.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchexim4< 4.60-3ubuntu3.1UNKNOWN
ubuntu6.06noarchmysql-dfsg-5.0< 5.0.22-0ubuntu6.06.3UNKNOWN
ubuntu6.10noarchmysql-dfsg-5.0< 5.0.24a-9ubuntu0.1UNKNOWN
ubuntu7.04noarchmysql-dfsg-5.0< 5.0.38-0ubuntu1UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.004

Percentile

74.7%