CVE Database
/

CVE-2008-2384

Back to search

CVE-2008-2384

Published: Jan 22, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

SQL injection vulnerability in mod_auth_mysql.c in the mod-auth-mysql (aka libapache2-mod-auth-mysql) module for the Apache HTTP Server 2.x, when configured to use a multibyte character set that allows a \ (backslash) as part of the character encoding, allows remote attackers to execute arbitrary SQL commands via unspecified inputs in a login request.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2009:0259
vendor-advisory
x_refsource_REDHAT
FEDORA-2011-0100
vendor-advisory
x_refsource_FEDORA
ADV-2011-0367
vdb-entry
x_refsource_VUPEN
FEDORA-2011-0114
vendor-advisory
x_refsource_FEDORA
33627
third-party-advisory
x_refsource_SECUNIA
43302
third-party-advisory
x_refsource_SECUNIA
RHSA-2010:1002
vendor-advisory
x_refsource_REDHAT
ADV-2009-0226
vdb-entry
x_refsource_VUPEN
oval:org.mitre.oval:def:10172
vdb-entry
signature
x_refsource_OVAL
33392
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now