Back to search
CVE-2008-4456
Published: Oct 6, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option is enabled, allows attackers to inject arbitrary web script or HTML by placing it in a database cell, which might be accessed by this client when composing an HTML document. NOTE: as of 20081031, the issue has not been fixed in MySQL 5.0.67.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20081029 Re: MySQL command-line client HTML injection vulnerability
mailing-list
x_refsource_BUGTRAQ
MDVSA-2009:094
vendor-advisory
x_refsource_MANDRIVA
USN-1397-1
vendor-advisory
x_refsource_UBUNTU
mysql-commandline-xss(45590)
vdb-entry
x_refsource_XF
oval:org.mitre.oval:def:11456
vdb-entry
signature
x_refsource_OVAL
20081008 Re: MySQL command-line client HTML injection vulnerability
mailing-list
x_refsource_BUGTRAQ
38517
third-party-advisory
x_refsource_SECUNIA
DSA-1783
vendor-advisory
x_refsource_DEBIAN
http://bugs.mysql.com/bug.php?id=27884
x_refsource_CONFIRM
USN-897-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2009:1289
vendor-advisory
x_refsource_REDHAT
32072
third-party-advisory
x_refsource_SECUNIA
APPLE-SA-2010-03-29-1
vendor-advisory
x_refsource_APPLE
20080930 MySQL command-line client HTML injection vulnerability
mailing-list
x_refsource_BUGTRAQ
http://support.apple.com/kb/HT4077
x_refsource_CONFIRM
RHSA-2010:0110
vendor-advisory
x_refsource_REDHAT
20081004 RE: RE: MySQL command-line client HTML injection vulnerability
mailing-list
x_refsource_BUGTRAQ
4357
third-party-advisory
x_refsource_SREASON
34907
third-party-advisory
x_refsource_SECUNIA
20080930 RE: MySQL command-line client HTML injection vulnerability
mailing-list
x_refsource_BUGTRAQ
36566
third-party-advisory
x_refsource_SECUNIA
31486
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now