SB2012081705 - SQL injection in Google, mysql



SB2012081705 - SQL injection in Google, mysql

Published: August 17, 2012 Updated: August 11, 2020

Security Bulletin ID SB2012081705
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) SQL injection (CVE-ID: CVE-2009-5026)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which the slave is running a newer version than the master, allows remote attackers to execute arbitrary SQL commands via custom comments.


Remediation

Install update from vendor's website.