CVE-2006-2753
published 2006-06-01CVE-2006-2753: SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via…
PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.54%
88.0th percentile
SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodings in character sets such as SJIS, BIG5, and GBK, which are not properly handled when the mysql_real_escape function is used to escape the input.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
MySQL vulnerability
vendor_ubuntu·2006-06-17
CVE-2006-2753 MySQL vulnerability
Title: MySQL vulnerability
Summary: MySQL vulnerability
An SQL injection vulnerability has been discovered when using less
popular multibyte encodings (such as SJIS, or BIG5) which contain
valid multibyte characters that end with the byte 0x5c (the
representation of the backslash character >>\>'>\'>'>'>''<<.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Ubuntu
PostgreSQL client vulnerabilities
vendor_ubuntu·2006-06-09·CVSS 7.5
CVE-2006-2314 [HIGH] PostgreSQL client vulnerabilities
Title: PostgreSQL client vulnerabilities
Summary: PostgreSQL client vulnerabilities
USN-288-1 described a PostgreSQL client vulnerability in the way
the >>'>'>\'>''>\>'>\'>'>''>\'>\'<< is now regarded as invalid when one of the affected client
encodings is in use. If you depend on the previous behaviour, you
can restore it by setting 'backslash_quote = on' in postgresql.conf.
However, please be aware that this could render you vulnerable
again.
This issue does not affect you if you only use single-byte (like
SQL_ASCII or the ISO-8859-X family) or unaffected multibyte (like
UTF-8) encodings.
Please see http://www.postgresql.org/docs/techdocs.50 for further
details.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
security flaw
vendor_redhat·2006-05-31·CVSS 7.5
CVE-2006-2753 [HIGH] security flaw
security flaw
SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodings in character sets such as SJIS, BIG5, and GBK, which are not properly handled when the mysql_real_escape function is used to escape the input.
GHSA
GHSA-qp7f-p87q-h2h6: SQL injection vulnerability in MySQL 4
ghsa_unreviewed·2022-05-01
CVE-2006-2753 [HIGH] GHSA-qp7f-p87q-h2h6: SQL injection vulnerability in MySQL 4
SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodings in character sets such as SJIS, BIG5, and GBK, which are not properly handled when the mysql_real_escape function is used to escape the input.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-2753 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-2006-2753 [HIGH] CVE-2006-2753 security flaw
CVE-2006-2753 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodings in character sets such as SJIS, BIG5, and GBK, which are not properly handled when the mysql_real_escape function is used to escape the input.
Bugzilla
CVE-2006-0903 Mysql multiple vulnerabilities (
bugzilla·2006-04-07·CVSS 4.6
CVE-2006-0903 [MEDIUM] CVE-2006-0903 Mysql multiple vulnerabilities (
CVE-2006-0903 Mysql multiple vulnerabilities (
+++ This bug was initially created as a clone of Bug #183261 +++
Mysql log file obfuscation
http://secunia.com/advisories/19034
The following text is from tgl:
Yeah, problem confirmed locally: the query log message is truncated,
060227 11:15:47 6 Connect root@localhost on test
6 Query /* x */ select 2+2
6 Quit
060227 11:16:24 7 Connect root@localhost on test
7 Query /*
7 Quit
The report is perhaps deliberately obscure: you can *not* exploit this
through mysql_query() because it expects a null-terminated string
anyway. But you can exploit it through mysql_real_query() which takes
a pointer and count.
I'd class the severity as pretty low, since all it allows is hiding
some traces of an attack after the attacker has already broken into
th
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=369735http://docs.info.apple.com/article.html?artnum=305214http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.htmlhttp://lists.mysql.com/announce/364http://secunia.com/advisories/20365http://secunia.com/advisories/20489http://secunia.com/advisories/20531http://secunia.com/advisories/20541http://secunia.com/advisories/20562http://secunia.com/advisories/20625http://secunia.com/advisories/20712http://secunia.com/advisories/24479http://securitytracker.com/id?1016216http://www.debian.org/security/2006/dsa-1092http://www.gentoo.org/security/en/glsa/glsa-200606-13.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:097http://www.redhat.com/support/errata/RHSA-2006-0544.htmlhttp://www.securityfocus.com/bid/18219http://www.trustix.org/errata/2006/0034/http://www.ubuntu.com/usn/usn-288-3http://www.us-cert.gov/cas/techalerts/TA07-072A.htmlhttp://www.vupen.com/english/advisories/2006/2105http://www.vupen.com/english/advisories/2007/0930https://exchange.xforce.ibmcloud.com/vulnerabilities/26875https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10312https://usn.ubuntu.com/303-1/http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=369735http://docs.info.apple.com/article.html?artnum=305214http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.htmlhttp://lists.mysql.com/announce/364http://secunia.com/advisories/20365http://secunia.com/advisories/20489http://secunia.com/advisories/20531http://secunia.com/advisories/20541http://secunia.com/advisories/20562http://secunia.com/advisories/20625http://secunia.com/advisories/20712http://secunia.com/advisories/24479http://securitytracker.com/id?1016216http://www.debian.org/security/2006/dsa-1092http://www.gentoo.org/security/en/glsa/glsa-200606-13.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:097http://www.redhat.com/support/errata/RHSA-2006-0544.htmlhttp://www.securityfocus.com/bid/18219http://www.trustix.org/errata/2006/0034/http://www.ubuntu.com/usn/usn-288-3http://www.us-cert.gov/cas/techalerts/TA07-072A.htmlhttp://www.vupen.com/english/advisories/2006/2105http://www.vupen.com/english/advisories/2007/0930https://exchange.xforce.ibmcloud.com/vulnerabilities/26875https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10312https://usn.ubuntu.com/303-1/
2006-06-01
Published